CVE-2016-1960

HIGH

Mozilla Firefox <45.0 - Firefox ESR 38.x <38.7 - RCE

Title source: llm

Description

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Rh0 · htmlremotewindows
https://www.exploit-db.com/exploits/44294
exploitdb WORKING POC
by Hans Jerry Illikainen · htmlremotewindows
https://www.exploit-db.com/exploits/42484

References (25)

... and 5 more

Scores

CVSS v3 8.8
EPSS 0.8706
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (22)
mozilla/firefox 38.0
mozilla/firefox 38.0.1
mozilla/firefox 38.0.5
mozilla/firefox 38.1.0
mozilla/firefox 38.1.1
mozilla/firefox 38.2.0
mozilla/firefox 38.2.1
mozilla/firefox 38.3.0
mozilla/firefox 38.4.0
mozilla/firefox 38.5.0
... and 12 more
Published Mar 13, 2016
Tracked Since Feb 18, 2026