CVE-2016-2837

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-2837
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2837.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-2837
Downstream
Related
Published
2016-08-05T01:59:03Z
Modified
2025-08-09T19:01:27Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing a malformed video and leveraging a Gecko Media Plugin (GMP) sandbox bypass.

References

Affected packages