CVE-2016-1961: Use After Free
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1961?
CVE-2016-1961 is a critical vulnerability that allows remote attackers to execute arbitrary code in affected versions of Mozilla Firefox and Firefox ESR.
How do I fix CVE-2016-1961?
To fix CVE-2016-1961, update Mozilla Firefox to version 45.0 or later, or Firefox ESR to version 38.7 or later.
Which software is affected by CVE-2016-1961?
CVE-2016-1961 affects Mozilla Firefox versions prior to 45.0 and Firefox ESR versions prior to 38.7, along with several openSUSE and Oracle Linux distributions.
What causes CVE-2016-1961?
CVE-2016-1961 is caused by a use-after-free vulnerability in the nsHTMLDocument::SetBody function due to mishandling of a root element.
Can CVE-2016-1961 be exploited remotely?
Yes, CVE-2016-1961 can be exploited remotely, allowing attackers to potentially execute arbitrary code on vulnerable systems.