CVE-2016-5287Use After Free in Mozilla Firefox

CWE-416Use After Free9 documents7 sources
Severity
9.8CRITICALNVD
EPSS
0.6%
top 31.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

debiandebian/firefox< firefox 50.0-1 (sid)
CVEListV5mozilla/firefoxunspecified49.0.2
NVDmozilla/firefox< 49.0.2
debiandebian/firefox-esr< firefox 50.0-1 (sid)
Ubuntumozilla/firefox< 49.0.2+build2-0ubuntu0.14.04.1+1

🔴Vulnerability Details

3
GHSA
GHSA-qpcp-783x-fcf2: A potentially exploitable use-after-free crash during actor destruction with service workers2022-05-14
OSV
firefox vulnerabilities2016-10-27
OSV
CVE-2016-5287: A potentially exploitable use-after-free crash during actor destruction with service workers2016-10-25

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-10-27
Red Hat
firefox: Crash in nsTArray_base2016-10-20
Debian
CVE-2016-5287: firefox - A potentially exploitable use-after-free crash during actor destruction with ser...2016

💬Community

2
Bugzilla
CVE-2016-5287 firefox: Crash in nsTArray_base2016-10-21
Bugzilla
CVE-2016-5287 CVE-2016-5288 firefox: various flaws [fedora-all]2016-10-21