CVE-2016-5254: Use After Free
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the nsXULPopupManager::KeyDown functio ...
— Debian
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-5254?
CVE-2016-5254 is a use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3.
How severe is CVE-2016-5254?
CVE-2016-5254 has a severity rating of 9.8 (critical).
How can CVE-2016-5254 be exploited?
CVE-2016-5254 can be exploited by attackers to execute arbitrary code or cause a denial of service by leveraging keyboard access to use the Alt key.
Which versions of Mozilla Firefox are affected by CVE-2016-5254?
Mozilla Firefox versions before 48.0 and Firefox ESR 45.x before 45.3 are affected by CVE-2016-5254.
Where can I find more information about CVE-2016-5254?
You can find more information about CVE-2016-5254 at the following references: 1. [CVE-2016-5254 on MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5254) 2. [Mozilla Security Advisory MFSΔ](https://www.mozilla.org/en-US/security/advisories/mfsa2016-70/) 3. [Bugzilla Mozilla - Issue 1266963](https://bugzilla.mozilla.org/show_bug.cgi?id=1266963)