CVE-2016-1960 describes an integer underflow vulnerability within the nsHtml5TreeBuilder class of Mozilla Firefox's HTML5 string parser, affecting Firefox before version 45.0 and Firefox ESR 38.x before 38.7, as well as products from OpenSUSE, Oracle, and SUSE. This flaw allows remote attackers to achieve arbitrary code execution or cause a denial-of-service via a use-after-free condition by manipulating end tags, particularly in SVG processing. Rated with a CVSS score of 8.8 (High), the vulnerability has a network attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability, requiring user interaction. While not listed on CISA's KEV catalog, exploit code exists on ExploitDB, and it has garnered significant community discussion and media coverage, indicating its past relevance and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
<= 44.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
38.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.