CVE-2016-5281

CVSS v3.0 9.8 (Critical)
98% Progress
CVSS v2.0 7.5 (High)
75% Progress
EPSS 2.89 % (91th)
2.89% Progress
Affected Products 2
Advisories 14

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.

Weaknesses
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2016-09-22 22:59:15
(8 years ago)
Updated Date
2018-10-30 16:27:02
(5 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox 48.0.2 and prior versions cpe:2.3:a:mozilla:firefox <= 48.0.2
  Mozilla Firefox 45.0.2 cpe:2.3:a:mozilla:firefox:45.0.2
  Mozilla Firefox Esr 45.0 cpe:2.3:a:mozilla:firefox_esr:45.0
  Mozilla Firefox Esr 45.0.1 cpe:2.3:a:mozilla:firefox_esr:45.0.1
  Mozilla Firefox Esr 45.1.1 cpe:2.3:a:mozilla:firefox_esr:45.1.1
  Mozilla Firefox Esr 45.2.0 cpe:2.3:a:mozilla:firefox_esr:45.2.0
  Mozilla Firefox Esr 45.3.0 cpe:2.3:a:mozilla:firefox_esr:45.3.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...