CVE-2016-5264: Use After Free
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-5264?
CVE-2016-5264 is a use-after-free vulnerability in Mozilla Firefox and Firefox ESR that allows remote attackers to execute arbitrary code or cause a denial of service.
What is the severity of CVE-2016-5264?
The severity of CVE-2016-5264 is high with a severity value of 8.8.
Which versions of Firefox are affected by CVE-2016-5264?
Mozilla Firefox versions up to and including 47.0.1 are affected by CVE-2016-5264.
Which versions of Firefox ESR are affected by CVE-2016-5264?
Mozilla Firefox ESR versions 45.1.0, 45.1.1, 45.2.0, and 45.3.0 are affected by CVE-2016-5264.
How can I fix CVE-2016-5264?
To fix CVE-2016-5264, upgrade to Mozilla Firefox version 48.0 or later, or upgrade to Mozilla Firefox ESR version 45.4.0 or later.