CVE-2016-2837 is a heap-based buffer overflow vulnerability affecting Mozilla Firefox and Firefox ESR versions prior to 48.0 and 45.3, respectively, as well as Oracle Firefox and Linux distributions. This flaw resides in the ClearKey Content Decryption Module (CDM) within the Encrypted Media Extensions (EME) API. Rated Medium (CVSS 6.3), a remote attacker could exploit this by providing a malformed video, potentially leveraging a Gecko Media Plugin (GMP) sandbox bypass to achieve arbitrary code execution, though user interaction is required. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 47.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
45.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.0:*:*:*:*:*:*:* | ||
45.1.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.1:*:*:*:*:*:*:* | ||
45.2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.2.0:*:*:*:*:*:*:* | ||
45.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.