CVE-2016-1960
8.8
HIGH
CVSS 3.1
EPSS 31.0%
Description
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
How to fix CVE-2016-1960
To remediate CVE-2016-1960, upgrade the affected package to a fixed version below.
- Debian/firefox-esr—upgrade to 45.0esr-1 or later
Is CVE-2016-1960 being exploited?
Moderate — EPSS is 31.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 45.0esr-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |