CVE-2016-2819

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

References

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html

http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00055.html

http://www.debian.org/security/2016/dsa-3600

http://www.mozilla.org/security/announce/2016/mfsa2016-50.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html

http://www.securityfocus.com/bid/91075

http://www.securitytracker.com/id/1036057

http://www.ubuntu.com/usn/USN-2993-1

https://access.redhat.com/errata/RHSA-2016:1217

https://bugzilla.mozilla.org/show_bug.cgi?id=1270381

https://www.exploit-db.com/exploits/44293/

Details

Source: MITRE

Published: 2016-06-13

Updated: 2018-10-30

Type: CWE-119

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (19 total)

IDNameProductFamilySeverity
93288SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nspr / mozilla-nss (SUSE-SU-2016:2061-1)NessusSuSE Local Security Checks
critical
93182SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLE / mozilla-nss (SUSE-SU-2016:1799-1)NessusSuSE Local Security Checks
high
93166SUSE SLED12 / SLES12 Security Update : MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss (SUSE-SU-2016:1691-1)NessusSuSE Local Security Checks
high
9383Mozilla Firefox < 47.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
9382Mozilla Firefox ESR < 45.2 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
91691Debian DLA-521-1 : firefox-esr security updateNessusDebian Local Security Checks
high
91648Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64 (20160608)NessusScientific Linux Local Security Checks
high
91635CentOS 5 / 6 / 7 : firefox (CESA-2016:1217)NessusCentOS Local Security Checks
high
91589openSUSE Security Update : MozillaFirefox / mozilla-nss (openSUSE-2016-714)NessusSuSE Local Security Checks
high
91586openSUSE Security Update : MozillaFirefox / mozilla-nss (openSUSE-2016-704)NessusSuSE Local Security Checks
high
91557Ubuntu 12.04 LTS / 14.04 LTS / 15.10 / 16.04 LTS : firefox vulnerabilities (USN-2993-1)NessusUbuntu Local Security Checks
high
91550Debian DSA-3600-1 : firefox-esr - security updateNessusDebian Local Security Checks
high
91547Firefox < 47 Multiple VulnerabilitiesNessusWindows
high
91546Firefox ESR 45.x < 45.2 Multiple VulnerabilitiesNessusWindows
high
91545Firefox < 47 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
91544Firefox ESR 45.x < 45.2 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
91536RHEL 5 / 6 / 7 : firefox (RHSA-2016:1217)NessusRed Hat Local Security Checks
high
91535Oracle Linux 5 / 6 / 7 : firefox (ELSA-2016-1217)NessusOracle Linux Local Security Checks
high
91509FreeBSD : mozilla -- multiple vulnerabilities (8065d37b-8e7c-4707-a608-1b0a2b8509c3)NessusFreeBSD Local Security Checks
high