CVE-2016-2811Firefox vulnerability

11 documents7 sources
Severity
8.8HIGHNVD
EPSS
1.7%
top 17.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 17

Description

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Ubuntumozilla/firefox< 46.0+build5-0ubuntu0.14.04.2+3
NVDmozilla/firefox45.0.2
debiandebian/firefox< firefox 46.0-1 (sid)
debiandebian/firefox-esr< firefox 46.0-1 (sid)

🔴Vulnerability Details

4
GHSA
GHSA-w92w-fc6m-j79x: Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 462022-05-17
OSV
firefox regression2016-05-19
OSV
CVE-2016-2811: Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 462016-04-27
OSV
firefox vulnerabilities2016-04-27

📋Vendor Advisories

5
Ubuntu
Firefox regression2016-05-19
Ubuntu
Oxygen-GTK3 update2016-05-02
Ubuntu
Firefox vulnerabilities2016-04-27
Red Hat
Mozilla: Use-after-free and buffer overflow in Service Workers (MFSA 2016-42)2016-04-26
Debian
CVE-2016-2811: firefox - Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worke...2016

💬Community

1
Bugzilla
CVE-2016-2811 Mozilla: Use-after-free and buffer overflow in Service Workers (MFSA 2016-42)2016-04-25