CVE-2016-5280: Use After Free
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.
— Launchpad
Use-after-free vulnerability when changing text direction
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2016-5280?
CVE-2016-5280 is a use-after-free vulnerability in Mozilla Firefox and Thunderbird that allows remote attackers to execute arbitrary code.
Which versions of Mozilla Firefox are affected by CVE-2016-5280?
Mozilla Firefox versions up to and including 48.0.2 are affected by CVE-2016-5280.
Which versions of Mozilla Firefox ESR are affected by CVE-2016-5280?
Mozilla Firefox ESR versions up to and including 45.4 are affected by CVE-2016-5280.
Which versions of Thunderbird are affected by CVE-2016-5280?
Thunderbird versions up to and including 45.4 are affected by CVE-2016-5280.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers to execute arbitrary code.