PT-2016-1454 · Mozilla+3 · Firefox+3

Oriol

+1

·

Published

2016-03-08

·

Updated

2024-12-12

·

CVE-2016-1963

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 45.0
Description The issue is related to the FileReader class in Mozilla Firefox, which has insufficient access control. This can be exploited by a local attacker to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
Recommendations For versions prior to 45.0, update to version 45.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the FileReader API until a patch is available.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1277
ALT-PU-2016-1454
BDU:2016-00755
CVE-2016-1963
OPENSUSE-SU-2016_0731-1
OPENSUSE-SU-2016_0733-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-2917-1
USN-2917-2
USN-2917-3

Affected Products

Alt Linux
Firefox
Suse
Ubuntu