8.8
CVSSv3

CVE-2016-2836

Published: 05/08/2016 Updated: 16/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox prior to 48.0 and Firefox ESR 45.x prior to 45.3 allow remote malicious users to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to Http2Session::Shutdown and SpdySession31::Shutdown, and other vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox esr 45.1.1

mozilla firefox esr 45.1.0

mozilla firefox esr 45.2.0

mozilla firefox esr 45.3.0

mozilla firefox

Vendor Advisories

Thunderbird could be made to crash or run programs as your login if it opened a malicious message ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Multiple security issues have been found in Icedove, Debian's version of the Mozilla Thunderbird mail client: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service For the stable distribution (jessie), this problem has been fixed in version 1:4530-1~deb8u1 For the unstable distribution (sid), this proble ...
Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the execution of arbitrary code, cross-site scripting, information disclosure and bypass of the same-origin policy For the stable distribution (jessie), these problems have been fi ...
Mozilla Foundation Security Advisory 2016-62 Miscellaneous memory safety hazards (rv:480 / rv:453) Announced August 2, 2016 Reporter Mozilla Developers Impact Critical Products Firefox, Firefox ESR, Thunderbird Fixed ...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 480 and Firefox ESR 45x before 453 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to Http2Session::Shutdown and SpdySession31::Shutdown, and other vectors ...