CVE-2016-1931

EUVD-2016-3020
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 43.0.4
opensuseleap
42.1
opensuseopensuse
13.1
opensuseopensuse
13.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 44.0+build3-0ubuntu0.12.04.1
released
trusty
Fixed 44.0+build3-0ubuntu0.14.04.1
released
vivid
Fixed 44.0+build3-0ubuntu0.15.04.1
released
wily
Fixed 44.0+build3-0ubuntu0.15.10.1
released
thunderbird
precise
not-affected
trusty
dne
vivid
not-affected
wily
not-affected
References