CVE-2016-1930

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

References

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00003.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00010.html

http://lists.opensuse.org/opensuse-updates/2016-02/msg00101.html

http://lists.opensuse.org/opensuse-updates/2016-02/msg00105.html

http://rhn.redhat.com/errata/RHSA-2016-0071.html

http://rhn.redhat.com/errata/RHSA-2016-0258.html

http://www.debian.org/security/2016/dsa-3457

http://www.debian.org/security/2016/dsa-3491

http://www.mozilla.org/security/announce/2016/mfsa2016-01.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html

http://www.securityfocus.com/bid/81953

http://www.securitytracker.com/id/1034825

http://www.ubuntu.com/usn/USN-2880-1

http://www.ubuntu.com/usn/USN-2880-2

http://www.ubuntu.com/usn/USN-2904-1

https://bugzilla.mozilla.org/show_bug.cgi?id=1221385

https://bugzilla.mozilla.org/show_bug.cgi?id=1223670

https://bugzilla.mozilla.org/show_bug.cgi?id=1224200

https://bugzilla.mozilla.org/show_bug.cgi?id=1230483

https://bugzilla.mozilla.org/show_bug.cgi?id=1230639

https://bugzilla.mozilla.org/show_bug.cgi?id=1230668

https://bugzilla.mozilla.org/show_bug.cgi?id=1230686

https://bugzilla.mozilla.org/show_bug.cgi?id=1233152

https://bugzilla.mozilla.org/show_bug.cgi?id=1233346

https://bugzilla.mozilla.org/show_bug.cgi?id=1233925

https://bugzilla.mozilla.org/show_bug.cgi?id=1234280

https://bugzilla.mozilla.org/show_bug.cgi?id=1234571

https://security.gentoo.org/glsa/201605-06

Details

Source: MITRE

Published: 2016-01-31

Updated: 2019-12-27

Type: CWE-119

Risk Information

CVSS v2

Base Score: 10

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (29 total)

IDNameProductFamilySeverity
802019Firefox < 44 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
critical
91379GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH)NessusGentoo Local Security Checks
critical
89776Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : thunderbird vulnerabilities (USN-2904-1) (SLOTH)NessusUbuntu Local Security Checks
critical
89021SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, MozillaFirefox-branding-SLES-for-VMware, mozilla-nss (SUSE-SU-2016:0584-1) (SLOTH)NessusSuSE Local Security Checks
critical
88943Debian DSA-3491-1 : icedove - security update (SLOTH)NessusDebian Local Security Checks
critical
9075Mozilla Firefox < 44.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical
88860Scientific Linux Security Update : thunderbird on SL5.x, SL6.x, SL7.x i386/x86_64 (20160218)NessusScientific Linux Local Security Checks
critical
88859RHEL 5 / 6 / 7 : thunderbird (RHSA-2016:0258)NessusRed Hat Local Security Checks
critical
88856Oracle Linux 6 / 7 : thunderbird (ELSA-2016-0258)NessusOracle Linux Local Security Checks
critical
88844CentOS 5 / 6 / 7 : thunderbird (CESA-2016:0258)NessusCentOS Local Security Checks
critical
88830openSUSE Security Update : Thunderbird (openSUSE-2016-225) (SLOTH)NessusSuSE Local Security Checks
critical
88827openSUSE Security Update : MozillaThunderbird (openSUSE-2016-222)NessusSuSE Local Security Checks
critical
88637Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : firefox regression (USN-2880-2)NessusUbuntu Local Security Checks
critical
88620SUSE SLED12 / SLES12 Security Update : MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss (SUSE-SU-2016:0338-1)NessusSuSE Local Security Checks
critical
88619SUSE SLED11 / SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nss (SUSE-SU-2016:0334-1)NessusSuSE Local Security Checks
critical
88552openSUSE Security Update : Mozilla Firefox (openSUSE-2016-131)NessusSuSE Local Security Checks
critical
88549openSUSE Security Update : the MozillaFirefox / mozilla-nss and mozilla-nspr (openSUSE-2016-128)NessusSuSE Local Security Checks
critical
88548openSUSE Security Update : xulrunner (openSUSE-2016-127)NessusSuSE Local Security Checks
critical
88512FreeBSD : mozilla -- multiple vulnerabilities (4f00dac0-1e18-4481-95af-7aaad63fd303)NessusFreeBSD Local Security Checks
critical
88461Firefox < 44 Multiple VulnerabilitiesNessusWindows
critical
88460Firefox ESR < 38.6 Multiple VulnerabilitiesNessusWindows
critical
88459Firefox < 44 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
88458Firefox ESR < 38.6 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
88456Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : firefox vulnerabilities (USN-2880-1)NessusUbuntu Local Security Checks
critical
88452Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64 (20160127)NessusScientific Linux Local Security Checks
critical
88443Oracle Linux 5 / 6 / 7 : firefox (ELSA-2016-0071)NessusOracle Linux Local Security Checks
critical
88426Debian DSA-3457-1 : iceweasel - security update (SLOTH)NessusDebian Local Security Checks
critical
88419CentOS 5 / 6 / 7 : firefox (CESA-2016:0071)NessusCentOS Local Security Checks
critical
88406RHEL 5 / 6 / 7 : firefox (RHSA-2016:0071)NessusRed Hat Local Security Checks
critical