Mozilla · Firefox Esr · CVE-2016-2821
**Name of the Vulnerable Software and Affected Versions**
Mozilla Firefox versions prior to 47.0
Mozilla Firefox ESR 45.x versions prior to 45.2
**Description**
The issue is related to a use-after-free vulnerability in the mozilla::dom::Element class. This occurs when contenteditable mode is enabled, allowing remote attackers to execute arbitrary code or cause a denial of service due to heap memory corruption. The vulnerability is triggered by the deletion of DOM elements that were created in the editor.
**Recommendations**
For Mozilla Firefox versions prior to 47.0, update to version 47.0 or later.
For Mozilla Firefox ESR 45.x versions prior to 45.2, update to version 45.2 or later.