CVE-2016-1945

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.

References

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html

http://www.mozilla.org/security/announce/2016/mfsa2016-10.html

http://www.securityfocus.com/bid/81950

http://www.securitytracker.com/id/1034825

http://www.ubuntu.com/usn/USN-2880-1

http://www.ubuntu.com/usn/USN-2880-2

https://bugzilla.mozilla.org/show_bug.cgi?id=1214782

https://security.gentoo.org/glsa/201605-06

Details

Source: MITRE

Published: 2016-01-31

Updated: 2018-10-30

Risk Information

CVSS v2

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
802019Firefox < 44 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
critical
91379GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH)NessusGentoo Local Security Checks
critical
9075Mozilla Firefox < 44.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical
88637Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : firefox regression (USN-2880-2)NessusUbuntu Local Security Checks
critical
88552openSUSE Security Update : Mozilla Firefox (openSUSE-2016-131)NessusSuSE Local Security Checks
critical
88549openSUSE Security Update : the MozillaFirefox / mozilla-nss and mozilla-nspr (openSUSE-2016-128)NessusSuSE Local Security Checks
critical
88512FreeBSD : mozilla -- multiple vulnerabilities (4f00dac0-1e18-4481-95af-7aaad63fd303)NessusFreeBSD Local Security Checks
critical
88461Firefox < 44 Multiple VulnerabilitiesNessusWindows
critical
88459Firefox < 44 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
88456Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : firefox vulnerabilities (USN-2880-1)NessusUbuntu Local Security Checks
critical