CVE-2016-1930

HIGH

Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

References

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00010.html

http://lists.opensuse.org/opensuse-updates/2016-02/msg00101.html

http://lists.opensuse.org/opensuse-updates/2016-02/msg00105.html

http://rhn.redhat.com/errata/RHSA-2016-0071.html

http://rhn.redhat.com/errata/RHSA-2016-0258.html

http://www.debian.org/security/2016/dsa-3457

http://www.debian.org/security/2016/dsa-3491

http://www.mozilla.org/security/announce/2016/mfsa2016-01.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html

http://www.securityfocus.com/bid/81953

http://www.securitytracker.com/id/1034825

http://www.ubuntu.com/usn/USN-2880-1

http://www.ubuntu.com/usn/USN-2880-2

http://www.ubuntu.com/usn/USN-2904-1

https://bugzilla.mozilla.org/show_bug.cgi?id=1221385

https://bugzilla.mozilla.org/show_bug.cgi?id=1223670

https://bugzilla.mozilla.org/show_bug.cgi?id=1224200

https://bugzilla.mozilla.org/show_bug.cgi?id=1230483

https://bugzilla.mozilla.org/show_bug.cgi?id=1230639

https://bugzilla.mozilla.org/show_bug.cgi?id=1230668

https://bugzilla.mozilla.org/show_bug.cgi?id=1230686

https://bugzilla.mozilla.org/show_bug.cgi?id=1233152

https://bugzilla.mozilla.org/show_bug.cgi?id=1233346

https://bugzilla.mozilla.org/show_bug.cgi?id=1233925

https://bugzilla.mozilla.org/show_bug.cgi?id=1234280

https://bugzilla.mozilla.org/show_bug.cgi?id=1234571

https://security.gentoo.org/glsa/201605-06

Details

Source: MITRE

Published: 2016-01-31

Updated: 2019-12-27

Type: CWE-119

Risk Information

CVSS v2.0

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

CVSS v3.0

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (29 total)

IDNameProductFamilySeverity
802019Firefox < 44 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
critical
91379GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH)NessusGentoo Local Security Checks
critical
89776Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : thunderbird vulnerabilities (USN-2904-1) (SLOTH)NessusUbuntu Local Security Checks
critical
89021SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, MozillaFirefox-branding-SLES-for-VMware, mozilla-nss (SUSE-SU-2016:0584-1) (SLOTH)NessusSuSE Local Security Checks
critical
88943Debian DSA-3491-1 : icedove - security update (SLOTH)NessusDebian Local Security Checks
critical
9075Mozilla Firefox < 44.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
88860Scientific Linux Security Update : thunderbird on SL5.x, SL6.x, SL7.x i386/x86_64 (20160218)NessusScientific Linux Local Security Checks
critical
88859RHEL 5 / 6 / 7 : thunderbird (RHSA-2016:0258)NessusRed Hat Local Security Checks
critical
88856Oracle Linux 6 / 7 : thunderbird (ELSA-2016-0258)NessusOracle Linux Local Security Checks
critical
88844CentOS 5 / 6 / 7 : thunderbird (CESA-2016:0258)NessusCentOS Local Security Checks
critical
88830openSUSE Security Update : Thunderbird (openSUSE-2016-225) (SLOTH)NessusSuSE Local Security Checks
critical
88827openSUSE Security Update : MozillaThunderbird (openSUSE-2016-222)NessusSuSE Local Security Checks
critical
88637Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : firefox regression (USN-2880-2)NessusUbuntu Local Security Checks
critical
88620SUSE SLED12 / SLES12 Security Update : MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss (SUSE-SU-2016:0338-1)NessusSuSE Local Security Checks
critical
88619SUSE SLED11 / SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nss (SUSE-SU-2016:0334-1)NessusSuSE Local Security Checks
critical
88552openSUSE Security Update : Mozilla Firefox (openSUSE-2016-131)NessusSuSE Local Security Checks
critical
88549openSUSE Security Update : the MozillaFirefox / mozilla-nss and mozilla-nspr (openSUSE-2016-128)NessusSuSE Local Security Checks
critical
88548openSUSE Security Update : xulrunner (openSUSE-2016-127)NessusSuSE Local Security Checks
critical
88512FreeBSD : mozilla -- multiple vulnerabilities (4f00dac0-1e18-4481-95af-7aaad63fd303)NessusFreeBSD Local Security Checks
critical
88461Firefox < 44 Multiple VulnerabilitiesNessusWindows
critical
88460Firefox ESR < 38.6 Multiple VulnerabilitiesNessusWindows
critical
88459Firefox < 44 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
88458Firefox ESR < 38.6 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
88456Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : firefox vulnerabilities (USN-2880-1)NessusUbuntu Local Security Checks
critical
88452Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64 (20160127)NessusScientific Linux Local Security Checks
critical
88443Oracle Linux 5 / 6 / 7 : firefox (ELSA-2016-0071)NessusOracle Linux Local Security Checks
critical
88426Debian DSA-3457-1 : iceweasel - security update (SLOTH)NessusDebian Local Security Checks
critical
88419CentOS 5 / 6 / 7 : firefox (CESA-2016:0071)NessusCentOS Local Security Checks
critical
88406RHEL 5 / 6 / 7 : firefox (RHSA-2016:0071)NessusRed Hat Local Security Checks
critical