CVE-2016-1974: Buffer Overflow
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1974?
CVE-2016-1974 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2016-1974?
To fix CVE-2016-1974, update Mozilla Firefox to version 45.0 or later, or to Firefox ESR version 38.7 or later.
Which versions of Firefox are affected by CVE-2016-1974?
Mozilla Firefox versions before 45.0 and Firefox ESR versions before 38.7 are affected by CVE-2016-1974.
What types of attacks can exploit CVE-2016-1974?
CVE-2016-1974 can be exploited through crafted Unicode data within HTML, potentially leading to arbitrary code execution or causing denial of service.
Is CVE-2016-1974 present in Mozilla Thunderbird?
Yes, versions of Mozilla Thunderbird up to 38.6.0 are also affected by CVE-2016-1974.