← All CVEs

CVE-2016-2819

high · 8.8

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

8.8
CVSS
24.0%
EPSS (exploit prob.)
98th
EPSS percentile
2016-06-13
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
opensuseleap42.1
opensuseopensuse13.1
opensuseopensuse13.2
mozillafirefox45.1.0
mozillafirefox45.1.1
debiandebian_linux8.0
mozillafirefox<= 46.0.1
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux15.10
canonicalubuntu_linux16.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-2819