CVE-2016-1960

Scores

EPSS

0.871high87.1%
0%20%40%60%80%100%

Percentile: 87.1%

CVSS

8.8high3.x
0246810

CVSS Score: 8.8/10

All CVSS Scores

CVSS 3.x
8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

Related Vulnerabilities

Exploits

Exploit ID: 42484

Source: exploitdb

URL: https://www.exploit-db.com/exploits/42484

Exploit ID: 44294

Source: exploitdb

URL: https://www.exploit-db.com/exploits/44294

Vulnerable Software (22)

Type: Configuration

Product: firefox

Operating System: debian

Trait:
{  "fixed": "45.0-1"}

Source: debian

Type: Configuration

Product: firefox

Operating System: ubuntu trusty 14.04

Trait:
{  "fixed": "45.0+build2-0ubuntu0.14.04.1"}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu wily 15.10

Trait:
{  "fixed": "45.0+build2-0ubuntu0.15.10.1"}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu xenial 16.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: rhel 5

Trait:
{  "fixed": "38.7.0-1.el5_11"}

Source: redhat

Type: Configuration

Product: firefox

Operating System: rhel 6

Trait:
{  "fixed": "38.7.0-1.el6_7"}

Source: redhat

Type: Configuration

Product: firefox

Operating System: rhel 7

Trait:
{  "fixed": "38.7.0-1.el7_2"}

Source: redhat

Type: Configuration

Product: firefox-esr

Operating System: debian

Trait:
{  "fixed": "45.0esr-1"}

Source: debian

Type: Configuration

Product: icedove

Operating System: debian

Trait:
{  "fixed": "38.7.0-1"}

Source: debian

Type: Configuration

Product: iceweasel

Operating System: debian

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: thunderbird

Operating System: ubuntu trusty 14.04

Trait:
{  "fixed": "1:38.7.2+build1-0ubuntu0.14.04.1"}

Source: ubuntu

Type: Configuration

Product: thunderbird

Operating System: ubuntu wily 15.10

Trait:
{  "fixed": "1:38.7.2+build1-0ubuntu0.15.10.1"}

Source: ubuntu

Type: Configuration

Product: thunderbird

Operating System: ubuntu xenial 16.04

Trait:
{  "fixed": "1:38.7.2+build1-0ubuntu0.16.04.1"}

Source: ubuntu

Type: Configuration

Product: thunderbird

Operating System: rhel 5

Trait:
{  "fixed": "38.7.0-1.el5_11"}

Source: redhat

Type: Configuration

Product: thunderbird

Operating System: rhel 6

Trait:
{  "fixed": "38.7.0-1.el6_7"}

Source: redhat

Type: Configuration

Product: thunderbird

Operating System: rhel 7

Trait:
{  "fixed": "38.7.0-1.el7_2"}

Source: redhat

Type: Configuration

Vendor: *

Product: firefox

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",      "versionEndIncluding": "44.0.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:mozill...

Source: nvd

Type: Configuration

Vendor: *

Product: leap

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",     ...

Source: nvd

Type: Configuration

Vendor: *

Product: linux_distro

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*",      "vulnerab...

Source: nvd

Type: Configuration

Vendor: *

Product: linux_enterprise

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",     ...

Source: nvd