CVE-2016-1966: High severity oracle linux vulnerability
The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference and memory corruption) via a crafted NPAPI plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1966?
CVE-2016-1966 is considered a critical vulnerability as it allows remote attackers to potentially execute arbitrary code or cause a denial of service.
How do I fix CVE-2016-1966?
To fix CVE-2016-1966, update Mozilla Firefox to version 45.0 or later, or update Firefox ESR to version 38.7 or later.
Which versions of Mozilla Firefox are affected by CVE-2016-1966?
CVE-2016-1966 affects Mozilla Firefox versions before 45.0 and Firefox ESR versions before 38.7.
Can CVE-2016-1966 affect other software?
Yes, CVE-2016-1966 affects various versions of Mozilla Thunderbird and specific versions of Oracle Linux.
What types of attacks can exploit CVE-2016-1966?
Exploitability of CVE-2016-1966 can lead to arbitrary code execution and denial of service through crafted NPAPI plugins.