CVE-2016-9898: Use After Free
Published Dec 13, 2016
·Updated
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor.
Affected Software
27 affected componentsFixes available
debian/firefox
118.0.2-1
debian/firefox-esr
91.12.0esr-1~deb10u1115.3.1esr-1~deb10u1102.15.0esr-1~deb11u1115.3.1esr-1~deb11u1102.15.1esr-1~deb12u1115.3.0esr-1~deb12u1115.3.0esr-1
Mozilla Thunderbird<45.6
45.6
Mozilla Firefox<50.1
50.1
Mozilla Firefox ESR<45.6
45.6
Debian Debian Linux=9.0
redhat Enterprise Linux=5.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Eus=7.3
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Mozilla Thunderbird<45.6.0
Mozilla Firefox<50.1.0
Mozilla Firefox ESR<45.6.0
Mozilla Firefox<45.6.0
Event History
Dec 13, 2016
CVE Published
via Mozilla·12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2016-9898?
CVE-2016-9898 has been categorized as a high-severity vulnerability due to its potential for exploitation and resulting crashes.
2
How do I fix CVE-2016-9898?
To fix CVE-2016-9898, update to Firefox version 50.1 or later, Firefox ESR version 45.6 or later, or Thunderbird version 45.6 or later.
3
What versions of Firefox are affected by CVE-2016-9898?
CVE-2016-9898 affects all Firefox versions prior to 50.1.
4
Which Thunderbird version is impacted by CVE-2016-9898?
CVE-2016-9898 impacts Thunderbird versions before 45.6.
5
Is Firefox ESR affected by CVE-2016-9898?
Yes, Firefox ESR versions before 45.6 are affected by CVE-2016-9898.