CVE-2016-2828Firefox vulnerability

8 documents7 sources
Severity
8.8HIGHNVD
EPSS
2.1%
top 15.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

Ubuntumozilla/firefox< 47.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox46.0.1+2
debiandebian/firefox< firefox 47.0-1 (sid)
debiandebian/firefox-esr< firefox 47.0-1 (sid)
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-fw74-c57g-483q: Use-after-free vulnerability in Mozilla Firefox before 472022-05-14
OSV
CVE-2016-2828: Use-after-free vulnerability in Mozilla Firefox before 472016-06-13
OSV
firefox vulnerabilities2016-06-09

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-06-09
Red Hat
Mozilla: Use-after-free when textures are used in WebGL operations after recycle pool destruction (MFSA 2016-56)2016-06-08
Debian
CVE-2016-2828: firefox - Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x...2016

💬Community

1
Bugzilla
CVE-2016-2828 Mozilla: Use-after-free when textures are used in WebGL operations after recycle pool destruction (MFSA 2016-56)2016-06-06
CVE-2016-2828 — Debian Firefox vulnerability | cvebase