CVE-2016-2811 is a critical use-after-free vulnerability in the ServiceWorkerInfo class within the Service Worker subsystem of Mozilla Firefox prior to version 46.0. This flaw allows remote attackers to execute arbitrary code by exploiting specific vectors related to the BeginReading method. With a CVSS v3 score of 8.8 (High), it presents a significant risk, requiring user interaction (UI:R) but with low attack complexity (AC:L) and the potential for high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available and it's not on CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 45.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.