CVE-2016-2821Out-of-bounds Write in Firefox

8 documents7 sources
Severity
7.5HIGHNVD
OSV8.8
EPSS
2.9%
top 13.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages6 packages

Ubuntumozilla/firefox< 47.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox46.0.1+2
debiandebian/firefox< firefox 47.0-1 (sid)
debiandebian/firefox-esr< firefox 47.0-1 (sid)
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-6f24-v3m3-vf5g: Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 472022-05-14
OSV
CVE-2016-2821: Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 472016-06-13
OSV
firefox vulnerabilities2016-06-09

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-06-09
Red Hat
Mozilla: Use-after-free deleting tables from a contenteditable document (MFSA 2016-51)2016-06-08
Debian
CVE-2016-2821: firefox - Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firef...2016

💬Community

1
Bugzilla
CVE-2016-2821 Mozilla: Use-after-free deleting tables from a contenteditable document (MFSA 2016-51)2016-06-06