CVE-2016-2821: Use After Free
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2821?
The severity of CVE-2016-2821 is considered high due to its potential to execute arbitrary code or cause denial of service.
How do I fix CVE-2016-2821?
To fix CVE-2016-2821, update to Mozilla Firefox version 47.0 or later, or Firefox ESR 45.2 or later.
Which versions of Firefox are affected by CVE-2016-2821?
CVE-2016-2821 affects Mozilla Firefox versions prior to 47.0 and Firefox ESR versions before 45.2.
What causes the vulnerability CVE-2016-2821?
CVE-2016-2821 is caused by a use-after-free vulnerability in the mozilla::dom::Element class when contenteditable mode is enabled.
Can CVE-2016-2821 affect web applications?
Yes, CVE-2016-2821 can affect web applications due to the ability of remote attackers to exploit the vulnerability.