Related Vulnerabilities: CVE-2016-5276  

A use-after-free vulnerability has been discovered in the mozilla::a11y::DocAccessible::ProcessInvalidationList function triggered by setting a aria-owns attribute.

Severity High

Remote Yes

Type Arbitrary code execution

Description

A use-after-free vulnerability has been discovered in the mozilla::a11y::DocAccessible::ProcessInvalidationList function triggered by setting a aria-owns attribute.

AVG-24 firefox 48.0.2-1 49.0-1 Critical Fixed

22 Sep 2016 ASA-201609-22 AVG-24 firefox Critical multiple issues

https://bugzilla.mozilla.org/show_bug.cgi?id=1287721