← Back

CVE-2016-2839

nvd nist
Published: Aug 5, 2016Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allows remote attackers to cause a denial of service (application crash) via a crafted video.

Affected (5)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
5 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Mozilla
Up to 47.0.1
Version 45.1.0
Version 45.1.1
Version 45.2.0
Version 45.3.0
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Ffmpeg
Ffmpeg
Version 0.10

References (16)

Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Issue TrackingPermissions Required
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions Required
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.