First published: Mon Jun 13 2016(Updated: )
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox ESR | <=45.1.1 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =15.10 | |
Ubuntu | =16.04 | |
SUSE Linux Enterprise Software Development Kit | =12.0 | |
SUSE Linux Enterprise Software Development Kit | =12.0-sp1 | |
SUSE Linux Enterprise Desktop | =12.0 | |
SUSE Linux Enterprise Desktop | =12.0-sp1 | |
SUSE Linux Enterprise Server | =12.0 | |
SUSE Linux Enterprise Server | =12.0-sp1 | |
SUSE Linux | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Firefox | <=46.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2815 is considered to have a high severity due to the potential for remote code execution and application crash.
CVE-2016-2815 affects Mozilla Firefox versions prior to 47.0 and Firefox ESR versions up to 45.1.1.
To fix CVE-2016-2815, update your Firefox installation to version 47.0 or later.
CVE-2016-2815 may result in application crashes, which could potentially lead to temporary data loss.
Yes, the risk of exploitation for CVE-2016-2815 is high, as it allows remote attackers to exploit the vulnerabilities without user interaction.