CVE-2016-2811
Gentoo Linux Security Advisory 201701-15
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.
Vulnerabilidad de uso después de liberación de memoria en la clase ServiceWorkerInfo en el subsistema Service Worker en Mozilla Firefox en versiones anteriores a 46.0 permite a atacantes remotos ejecutar código arbitrario a través de vectores relacionados con el método BeginReading.
Christian Holler, Tyson Smith, Phil Ringalda, Gary Kwong, Jesse Ruderman, Mats Palmgren, Carsten Book, Boris Zbarsky, David Bolter, Randell Jesup, Andrew McCreight, and Steve Fink discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-03-01 CVE Reserved
- 2016-04-28 CVE Published
- 2024-08-05 CVE Updated
- 2025-01-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1035692 | Vdb Entry | |
https://bugzilla.mozilla.org/show_bug.cgi?id=1252330 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00005.html | 2017-07-01 | |
http://lists.opensuse.org/opensuse-updates/2016-05/msg00038.html | 2017-07-01 | |
http://www.mozilla.org/security/announce/2016/mfsa2016-42.html | 2017-07-01 | |
http://www.ubuntu.com/usn/USN-2936-1 | 2017-07-01 | |
http://www.ubuntu.com/usn/USN-2936-2 | 2017-07-01 | |
http://www.ubuntu.com/usn/USN-2936-3 | 2017-07-01 | |
https://security.gentoo.org/glsa/201701-15 | 2017-07-01 |