CVE-2016-2824: Buffer Overflow
The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2824?
CVE-2016-2824 is classified as a denial of service vulnerability that can lead to application crashes.
How do I fix CVE-2016-2824?
To fix CVE-2016-2824, update Mozilla Firefox to version 47.0 or later or apply the patches provided in the latest security updates.
Which versions of Mozilla Firefox are affected by CVE-2016-2824?
CVE-2016-2824 affects Mozilla Firefox versions up to 46.0.1 and Firefox ESR versions prior to 45.2.
Is Microsoft Windows affected by CVE-2016-2824?
No, Microsoft Windows is not directly affected by CVE-2016-2824, but vulnerable applications running on Windows are.
What impact does CVE-2016-2824 have on users?
Users may experience application crashes and potential denial of service when exploiting CVE-2016-2824 through specific WebGL shader usage.