CVE-2016-5256 describes multiple unspecified vulnerabilities within the browser engine of Mozilla Firefox, affecting versions prior to 49.0. These flaws could be remotely triggered, leading to a denial of service through memory corruption and application crashes, or potentially enabling arbitrary code execution. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over a network with low attack complexity, posing high impacts to confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed on the KEV catalog, its EPSS score and community discussion indicate some level of awareness, and it received media coverage upon its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 48.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.