CVE-2016-5264

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.

References

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html

http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00029.html

http://rhn.redhat.com/errata/RHSA-2016-1551.html

http://www.debian.org/security/2016/dsa-3640

http://www.mozilla.org/security/announce/2016/mfsa2016-79.html

http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html

http://www.securityfocus.com/bid/92258

http://www.securitytracker.com/id/1036508

http://www.ubuntu.com/usn/USN-3044-1

https://bugzilla.mozilla.org/show_bug.cgi?id=1286183

https://security.gentoo.org/glsa/201701-15

Details

Source: MITRE

Published: 2016-08-05

Updated: 2019-12-27

Type: CWE-416

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
96276GLSA-201701-15 : Mozilla Firefox, Thunderbird: Multiple vulnerabilities (SWEET32)NessusGentoo Local Security Checks
critical
93706openSUSE Security Update : Thunderbird (openSUSE-2016-1120)NessusSuSE Local Security Checks
critical
93429FreeBSD : Mozilla -- multiple vulnerabilities (aa1aefe3-6e37-47db-bfda-343ef4acb1b5)NessusFreeBSD Local Security Checks
critical
93363openSUSE Security Update : MozillaThunderbird (openSUSE-2016-1057)NessusSuSE Local Security Checks
critical
93313SUSE SLES11 Security Update : MozillaFirefox (SUSE-SU-2016:2195-1)NessusSuSE Local Security Checks
critical
93302SUSE SLED12 / SLES12 Security Update : MozillaFirefox (SUSE-SU-2016:2131-1)NessusSuSE Local Security Checks
critical
93288SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nspr / mozilla-nss (SUSE-SU-2016:2061-1)NessusSuSE Local Security Checks
critical
9485Mozilla Firefox ESR < 45.3 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
9484Mozilla Firefox < 48.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
92853openSUSE Security Update : MozillaFirefox / mozilla-nss (openSUSE-2016-960)NessusSuSE Local Security Checks
critical
92785Ubuntu 12.04 LTS / 14.04 LTS / 16.04 LTS : firefox vulnerabilities (USN-3044-1)NessusUbuntu Local Security Checks
critical
92755Firefox < 48 Multiple VulnerabilitiesNessusWindows
high
92754Firefox ESR 45.x < 45.3 Multiple VulnerabilitiesNessusWindows
critical
92753Firefox < 48 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
92752Firefox ESR 45.x < 45.3 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
92746openSUSE Security Update : MozillaFirefox / mozilla-nss (openSUSE-2016-937)NessusSuSE Local Security Checks
critical
92731Debian DSA-3640-1 : firefox-esr - security updateNessusDebian Local Security Checks
critical
92728Debian DLA-585-1 : firefox-esr security updateNessusDebian Local Security Checks
critical
92721Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64 (20160803)NessusScientific Linux Local Security Checks
critical
92717RHEL 5 / 6 / 7 : firefox (RHSA-2016:1551)NessusRed Hat Local Security Checks
critical
92716Oracle Linux 5 / 6 / 7 : firefox (ELSA-2016-1551)NessusOracle Linux Local Security Checks
critical
92703CentOS 5 / 6 / 7 : firefox (CESA-2016:1551)NessusCentOS Local Security Checks
critical