PT-2016-1451 · Mozilla+6 · Firefox Esr+7

Nicholas Nethercote

·

Published

2016-03-08

·

Updated

2024-12-12

·

CVE-2016-1966

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 45.0 Firefox ESR versions prior to 38.7
Description The issue is related to errors in pointer dereferencing in the nsNPObjWrapper::GetNewOrUsed function, which can be exploited by a remote attacker using a specially crafted NPAPI plugin. This exploitation can lead to the execution of arbitrary code or cause a denial of service due to memory corruption.
Recommendations For Mozilla Firefox versions prior to 45.0, update to version 45.0 or later. For Firefox ESR versions prior to 38.7, update to version 38.7 or later.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1250
ALT-PU-2016-1277
ALT-PU-2016-1454
BDU:2016-00752
CESA-2016_0373
CESA-2016_0460
CVE-2016-1966
DSA-3510-1
DSA-3520-1
MGASA-2016-0105
MGASA-2016-0115
OPENSUSE-SU-2016_0731-1
OPENSUSE-SU-2016_0733-1
OPENSUSE-SU-2016_0876-1
OPENSUSE-SU-2016_0894-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2016:0373
RHSA-2016:0460
RHSA-2016_0373
RHSA-2016_0460
SUSE-SU-2016:0727-1
SUSE-SU-2016:0777-1
SUSE-SU-2016:0909-1
USN-2917-1
USN-2917-2
USN-2917-3
USN-2934-1

Affected Products

Alt Linux
Centos
Firefox Esr
Firefox
Npapi
Red Hat
Suse
Ubuntu