CVE-2016-2808
Summary
| CVE | CVE-2016-2808 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-04-30 17:59:00 UTC |
| Updated | 2017-07-01 01:29:00 UTC |
| Description | The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code or cause a denial of service (generation-count overflow, out-of-bounds HashMap write access, and application crash) via a crafted web site. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| Mozilla Firefox, Thunderbird: Multiple vulnerabilities (GLSA 201701-15) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [security-announce] openSUSE-SU-2016:1211-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| openSUSE-SU-2016:1251-1: moderate: Security update to Firefox 46.0 |
SUSE |
lists.opensuse.org |
|
| 1246061 - (CVE-2016-2808) null-byte written out of bounds using .watch() due to generation count overflow |
CONFIRM |
bugzilla.mozilla.org |
|
| USN-2936-2: Oxygen-GTK3 update | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Oracle Linux Bulletin - April 2016 |
CONFIRM |
www.oracle.com |
|
| USN-2936-1: Firefox vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| [security-announce] SUSE-SU-2016:1258-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| Write to invalid HashMap entry through JavaScript.watch() — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| USN-2936-3: Firefox regression | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| [security-announce] SUSE-SU-2016:1374-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Gain Elevated Privileges, Bypass Security Restrictions, and Obtain Potentially Sensitive Information - SecurityTracker |
SECTRACK |
www.securitytracker.com |
|
| Debian -- Security Information -- DSA-3559-1 iceweasel |
DEBIAN |
www.debian.org |
|
| [security-announce] SUSE-SU-2016:1352-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710500 Gentoo Linux Mozilla Firefox, Thunderbird Multiple Vulnerabilities (GLSA 201701-15)