Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.html
http://www.mozilla.org/security/announce/2016/mfsa2016-32.html
http://www.securityfocus.com/bid/84220
http://www.securitytracker.com/id/1035215
Source: MITRE
Published: 2016-03-13
Updated: 2016-12-03
Type: NVD-CWE-Other
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.8
Severity: HIGH
AND
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
802023 | Firefox < 45 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | critical |
91379 | GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH) | Nessus | Gentoo Local Security Checks | critical |
9207 | Mozilla Firefox < 45.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
89915 | openSUSE Security Update : Firefox (openSUSE-2016-334) | Nessus | SuSE Local Security Checks | critical |
89913 | openSUSE Security Update : MozillaFirefox / mozilla-nspr / mozilla-nss (openSUSE-2016-332) | Nessus | SuSE Local Security Checks | critical |
89875 | Firefox < 45 Multiple Vulnerabilities | Nessus | Windows | critical |
89873 | Firefox < 45 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
89765 | FreeBSD : mozilla -- multiple vulnerabilities (2225c5b4-1e5a-44fc-9920-b3201c384a15) | Nessus | FreeBSD Local Security Checks | critical |