CVE-2016-2812Race Condition in Firefox

CWE-362Race Condition11 documents7 sources
Severity
7.5HIGHNVD
OSV8.8
EPSS
0.6%
top 29.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 17

Description

Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages4 packages

Ubuntumozilla/firefox< 46.0+build5-0ubuntu0.14.04.2+3
NVDmozilla/firefox45.0.2
debiandebian/firefox< firefox 46.0-1 (sid)
debiandebian/firefox-esr< firefox 46.0-1 (sid)

🔴Vulnerability Details

4
GHSA
GHSA-j6xp-8wg9-2gf2: Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 462022-05-17
OSV
firefox regression2016-05-19
OSV
CVE-2016-2812: Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 462016-04-27
OSV
firefox vulnerabilities2016-04-27

📋Vendor Advisories

5
Ubuntu
Firefox regression2016-05-19
Ubuntu
Oxygen-GTK3 update2016-05-02
Ubuntu
Firefox vulnerabilities2016-04-27
Red Hat
Mozilla: Use-after-free and buffer overflow in Service Workers (MFSA 2016-42)2016-04-26
Debian
CVE-2016-2812: firefox - Race condition in the get implementation in the ServiceWorkerManager class in th...2016

💬Community

1
Bugzilla
CVE-2016-2812 Mozilla: Use-after-free and buffer overflow in Service Workers (MFSA 2016-42)2016-04-25