CVE-2016-5252: Buffer Overflow
Last updated 24 July 2024
Other sources
Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data that is mishandled during clipping-region calculations.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-5252?
CVE-2016-5252 is a vulnerability in Mozilla Firefox and Firefox ESR that allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data.
What is the severity of CVE-2016-5252?
CVE-2016-5252 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2016-5252?
Oracle Linux versions 5.0, 6, and 7, Mozilla Firefox versions up to 47.0.1, and Mozilla Firefox ESR versions 45.1.0, 45.1.1, 45.2.0, and 45.3.0 are affected by CVE-2016-5252.
How can I fix CVE-2016-5252?
To fix CVE-2016-5252, update Mozilla Firefox to version 48.0 or newer, or update Mozilla Firefox ESR to version 45.3.0 or newer.
Where can I find more information about CVE-2016-5252?
More information about CVE-2016-5252 can be found on the CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5252), Mozilla security advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2016-67/), and Bugzilla (https://bugzilla.mozilla.org/show_bug.cgi?id=1268854).