CVE-2016-1964: Use After Free
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1964?
CVE-2016-1964 has a severity rating that indicates it can lead to remote code execution or denial of service due to heap memory corruption.
How do I fix CVE-2016-1964?
To remediate CVE-2016-1964, update to Mozilla Firefox version 45.0 or later, or Mozilla Firefox ESR version 38.7 or later.
Which versions of Firefox are affected by CVE-2016-1964?
CVE-2016-1964 affects Mozilla Firefox versions up to 44.0.2 and Firefox ESR versions prior to 38.7.
Can CVE-2016-1964 affect systems running Thunderbird?
Yes, the vulnerability can affect systems running Mozilla Thunderbird versions up to 38.6.0.
What type of exploit is associated with CVE-2016-1964?
CVE-2016-1964 is associated with a use-after-free vulnerability that can be exploited through mishandling of XML transformations.