First published: Sat Apr 30 2016(Updated: )
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=45.0.2 | |
Mozilla Firefox | =45.0.1 | |
Mozilla Firefox ESR | =38.0 | |
Mozilla Firefox ESR | =38.0.1 | |
Mozilla Firefox ESR | =38.0.5 | |
Mozilla Firefox ESR | =38.1.0 | |
Mozilla Firefox ESR | =38.1.1 | |
Mozilla Firefox ESR | =38.2.0 | |
Mozilla Firefox ESR | =38.2.1 | |
Mozilla Firefox ESR | =38.3.0 | |
Mozilla Firefox ESR | =38.4.0 | |
Mozilla Firefox ESR | =38.5.0 | |
Mozilla Firefox ESR | =38.5.1 | |
Mozilla Firefox ESR | =38.6.0 | |
Mozilla Firefox ESR | =38.6.1 | |
Mozilla Firefox ESR | =38.7.0 | |
Mozilla Firefox ESR | =38.7.1 | |
openSUSE | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Server | =12.0 | |
Mozilla Firefox | =38.0 | |
Mozilla Firefox | =38.0.1 | |
Mozilla Firefox | =38.0.5 | |
Mozilla Firefox | =38.1.0 | |
Mozilla Firefox | =38.1.1 | |
Mozilla Firefox | =38.2.0 | |
Mozilla Firefox | =38.2.1 | |
Mozilla Firefox | =38.3.0 | |
Mozilla Firefox | =38.4.0 | |
Mozilla Firefox | =38.5.0 | |
Mozilla Firefox | =38.5.1 | |
Mozilla Firefox | =38.6.0 | |
Mozilla Firefox | =38.6.1 | |
Mozilla Firefox | =38.7.0 | |
Mozilla Firefox | =38.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2807 is classified as a critical vulnerability that can lead to denial of service or arbitrary code execution.
To address CVE-2016-2807, upgrade to Mozilla Firefox version 46.0 or later, or apply available patches for affected versions.
CVE-2016-2807 affects Mozilla Firefox versions prior to 46.0 and Firefox ESR versions before 38.8 and 45.1.
Yes, CVE-2016-2807 can be exploited by remote attackers to cause memory corruption and application crashes.
Users of affected Firefox versions may experience application crashes or may be vulnerable to code execution attacks.