Aller au contenu
appaloosa scout logo main rounded
HIGH 8.8

CVE-2016-1960

EN Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 86.5% percentile 99.4%

Apps suivies affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
mozilla thunderbird Windows ≤38.6.0 cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Voir sur NVD ↗