CVE-2016-5297Integer Overflow or Wraparound in Mozilla Firefox

Severity
9.8CRITICALNVD
EPSS
1.8%
top 17.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

debiandebian/firefox< firefox 50.0-1 (sid)
CVEListV5mozilla/firefoxunspecified50
NVDmozilla/firefox< 45.5.0+1
debiandebian/firefox-esr< firefox 50.0-1 (sid)
CVEListV5mozilla/firefox_esrunspecified45.5

Also affects: Debian Linux 8.0

🔴Vulnerability Details

4
GHSA
GHSA-3h9f-q3m2-wjhj: An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues2022-05-14
OSV
CVE-2016-5297: An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues2018-06-11
OSV
thunderbird vulnerabilities2016-12-01
OSV
firefox vulnerabilities2016-11-19

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2016-12-01
Ubuntu
Firefox vulnerabilities2016-11-19
Red Hat
Mozilla: Incorrect argument length checking in Javascript (MFSA 2016-89, MFSA 2016-90)2016-11-16
Debian
CVE-2016-5297: firefox - An error in argument length checking in JavaScript, leading to potential integer...2016

💬Community

1
Bugzilla
CVE-2016-5297 Mozilla: Incorrect argument length checking in Javascript (MFSA 2016-89, MFSA 2016-90)2016-11-15
CVE-2016-5297 — Integer Overflow or Wraparound | cvebase