Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-1960


Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.


Published

2016-03-13T18:59:09.617

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System oracle linux 5.0 Yes
Operating System oracle linux 6 Yes
Operating System oracle linux 7 Yes
Application mozilla firefox ≤ 44.0.2 Yes
Application mozilla firefox 38.0 Yes
Application mozilla firefox 38.0.1 Yes
Application mozilla firefox 38.0.5 Yes
Application mozilla firefox 38.1.0 Yes
Application mozilla firefox 38.1.1 Yes
Application mozilla firefox 38.2.0 Yes
Application mozilla firefox 38.2.1 Yes
Application mozilla firefox 38.3.0 Yes
Application mozilla firefox 38.4.0 Yes
Application mozilla firefox 38.5.0 Yes
Application mozilla firefox 38.5.1 Yes
Application mozilla firefox 38.6.0 Yes
Application mozilla firefox 38.6.1 Yes
Application mozilla thunderbird ≤ 38.6.0 Yes
Operating System opensuse leap 42.1 Yes
Operating System opensuse opensuse 13.1 Yes
Operating System opensuse opensuse 13.2 Yes
Operating System suse linux_enterprise 12.0 Yes

References