CVE-2016-2814 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Firefox
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer11 documents7 sources
Severity
8.8HIGHNVD
EPSS
2.1%
top 15.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 30
Latest updateMay 17
Description
Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
4GHSA▶
GHSA-5w2r-q893-4x6m: Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46↗2022-05-17
OSV▶
CVE-2016-2814: Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46↗2016-04-30
📋Vendor Advisories
5Debian▶
CVE-2016-2814: firefox - Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo ...↗2016
💬Community
1Bugzilla▶
CVE-2016-2814 Mozilla: Buffer overflow in libstagefright with CENC offsets (MFSA 2016-44)↗2016-04-25