CVE-2016-5272 is a critical vulnerability affecting Mozilla Firefox versions prior to 49.0, Firefox ESR 45.x before 45.4, and Thunderbird before 45.4. It stems from improper casting within the nsImageGeometryMixin class when handling INPUT elements, allowing remote attackers to execute arbitrary code through a crafted website. With a CVSS score of 8.8 (High), this vulnerability is easily exploitable over a network with low attack complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While no active exploits, Metasploit modules, or ExploitDB entries are publicly available, and community discussion is minimal, the high CVSS score indicates a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 48.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
45.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.0:*:*:*:*:*:*:* | ||
45.1.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.1.1:*:*:*:*:*:*:* | ||
45.2.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.2.0:*:*:*:*:*:*:* | ||
45.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:45.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.