CVE-2016-2838: Buffer Overflow
Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-2838?
CVE-2016-2838 is a vulnerability in Mozilla Firefox that allows remote attackers to execute arbitrary code via directional content in an SVG document.
How severe is CVE-2016-2838?
CVE-2016-2838 has a severity score of 8.8, which is considered high.
Which software versions are affected by CVE-2016-2838?
Mozilla Firefox versions before 48.0 and Firefox ESR versions before 45.3 are affected by CVE-2016-2838.
How can I fix CVE-2016-2838?
To fix CVE-2016-2838, update Mozilla Firefox to version 48.0 or later, or update Firefox ESR to version 45.3 or later.
Where can I find more information about CVE-2016-2838?
More information about CVE-2016-2838 can be found on the MITRE website and the Mozilla security advisories.