CVE Vulnerabilities

CVE-2016-2828

Published: Jun 13, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the textures recycle pool.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical12.04 (including)12.04 (including)
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
Ubuntu_linuxCanonical15.10 (including)15.10 (including)
Ubuntu_linuxCanonical16.04 (including)16.04 (including)
Red Hat Enterprise Linux 5RedHatfirefox-0:45.2.0-1.el5_11*
Red Hat Enterprise Linux 6RedHatfirefox-0:45.2.0-1.el6_8*
Red Hat Enterprise Linux 7RedHatfirefox-0:45.2.0-1.el7_2*
FirefoxUbuntudevel*
FirefoxUbuntuprecise*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuwily*
FirefoxUbuntuxenial*

References