Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1960

Опубликовано: 13 мар. 2016
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 8.8

Описание

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

РелизСтатусПримечание
devel

not-affected

45.0+build2-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [45.0+build2-0ubuntu0.14.04.1]]
precise

released

45.0+build2-0ubuntu0.12.04.1
trusty

released

45.0+build2-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [45.0+build2-0ubuntu0.14.04.1]
upstream

released

45.0
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

released

45.0+build2-0ubuntu0.15.10.1
xenial

not-affected

45.0+build2-0ubuntu1

Показывать по

РелизСтатусПримечание
devel

released

1:38.8.0+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:38.7.2+build1-0ubuntu0.14.04.1]]
precise

released

1:38.7.2+build1-0ubuntu0.12.04.1
trusty

released

1:38.7.2+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:38.7.2+build1-0ubuntu0.14.04.1]
upstream

released

38.7
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

released

1:38.7.2+build1-0ubuntu0.15.10.1
xenial

released

1:38.7.2+build1-0ubuntu0.16.04.1

Показывать по

6.8 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

redhat
больше 9 лет назад

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

CVSS3: 8.8
nvd
больше 9 лет назад

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

CVSS3: 8.8
debian
больше 9 лет назад

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string ...

CVSS3: 8.8
github
больше 3 лет назад

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

fstec
больше 9 лет назад

Уязвимость почтового клиента Thunderbird, браузеров Firefox и Firefox ESR, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

6.8 Medium

CVSS2

8.8 High

CVSS3