CVE-2016-2818 describes multiple unspecified memory corruption vulnerabilities within the browser engine of Mozilla Firefox versions prior to 47.0 and Firefox ESR 45.x before 45.2. These flaws affect various distributions including Canonical, Debian, and Red Hat. With a CVSS v3 score of 8.8 (HIGH), this vulnerability is remotely exploitable with low attack complexity, requiring user interaction. Successful exploitation could lead to a denial of service (application crash) or potentially arbitrary code execution, resulting in high impacts to confidentiality, integrity, and availability. Despite its high severity, CVE-2016-2818 is not listed in CISA's KEV catalog and there is no public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited active exploitation or widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
45.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.0:*:*:*:*:*:*:* | ||
45.1.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.1:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.