CVE-2016-2835: High severity Mozilla Firefox vulnerability
Last updated 24 July 2024
Other sources
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 137.0.2-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.9.0esr-1~deb11u1Fixed in 128.8.0esr-1~deb12u1Fixed in 128.9.0esr-1~deb12u1Fixed in 128.9.0esr-2 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 48.0
Event History
Frequently Asked Questions
What is CVE-2016-2835?
CVE-2016-2835 is a vulnerability in Mozilla Firefox before version 48.0 that allows remote attackers to cause a denial of service or possibly execute arbitrary code.
How severe is CVE-2016-2835?
CVE-2016-2835 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2016-2835?
Mozilla Firefox before version 48.0 is affected by CVE-2016-2835.
How can I fix CVE-2016-2835?
To fix CVE-2016-2835, you should update Mozilla Firefox to version 48.0 or higher.
Where can I find more information about CVE-2016-2835?
You can find more information about CVE-2016-2835 on the MITRE CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2835), the Mozilla Security Advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2016-62/), and the Bugzilla page (https://bugzilla.mozilla.org/buglist.cgi?bug_id=1254106,1264998,1270537,1282246,1251308,1280215,1280443,1222101,1275582).