CVE-2016-1935

Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
opensuseleap
42.1
opensuseopensuse
13.1
opensuseopensuse
13.2
oraclelinux
5.0
mozillafirefox
𝑥
≤ 43.0.4
mozillafirefox
38.0
mozillafirefox
38.1.0
mozillafirefox
38.2.0
mozillafirefox
38.3.0
mozillafirefox
38.4.0
mozillafirefox
38.5.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
wily
Fixed 44.0+build3-0ubuntu0.15.10.1
released
vivid
Fixed 44.0+build3-0ubuntu0.15.04.1
released
trusty
Fixed 44.0+build3-0ubuntu0.14.04.1
released
precise
Fixed 44.0+build3-0ubuntu0.12.04.1
released
thunderbird
wily
Fixed 1:38.6.0+build1-0ubuntu0.15.10.1
released
vivid
ignored
trusty
Fixed 1:38.6.0+build1-0ubuntu0.14.04.1
released
precise
Fixed 1:38.6.0+build1-0ubuntu0.12.04.1
released
References