Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto, Tyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1952, CVE-2016-1953)
Nicolas Golubovic discovered that CSP violation reports can be used to overwrite local files. If a user were tricked in to opening a specially crafted website with addon signing disabled and unpacked addons installed, an attacker could potentially exploit this to gain additional privileges. (CVE-2016-1954)
Muneaki Nishimura discovered that CSP violation reports contained full paths for cross-origin iframe navigations. An attacker could potentially exploit this to steal confidential data. (CVE-2016-1955)
Ucha Gobejishvili discovered that performing certain WebGL operations resulted in memory resource exhaustion with some Intel GPUs, requiring a reboot. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service. (CVE-2016-1956)
Jose Martinez and Romina Santillan discovered a memory leak in libstagefright during MPEG4 video file processing in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via memory exhaustion. (CVE-2016-1957)
Abdulrahman Alqabandi discovered that the addressbar could be blank or filled with page defined content in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to conduct URL spoofing attacks. (CVE-2016-1958)
Looben Yang discovered an out-of-bounds read in Service Worker Manager. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1959)
A use-after-free was discovered in the HTML5 string parser. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1960)
A use-after-free was discovered in the SetBody function of HTMLDocument. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1961)
Dominique Hazaël-Massieux discovered a use-after-free when using multiple WebRTC data channels. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1962)
It was discovered that Firefox crashes when local files are modified whilst being read by the FileReader API. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1963)
Nicolas Grégoire discovered a use-after-free during XML transformations. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1964)
Tsubasa Iinuma discovered a mechanism to cause the addressbar to display an incorrect URL, using history navigations and the Location protocol property. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to conduct URL spoofing attacks. (CVE-2016-1965)
A memory corruption issues was discovered in the NPAPI subsystem. If a user were tricked in to opening a specially crafted website with a malicious plugin installed, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1966)
Jordi Chancel discovered a same-origin-policy bypass when using performance.getEntries and history navigation with session restore. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to steal confidential data. (CVE-2016-1967)
Luke Li discovered a buffer overflow during Brotli decompression in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1968)
Ronald Crane discovered a use-after-free in GetStaticInstance in WebRTC. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1973)
Ronald Crane discovered an out-of-bounds read following a failed allocation in the HTML parser in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1974)
Holger Fuhrmannek, Tyson Smith and Holger Fuhrmannek reported multiple memory safety issues in the Graphite 2 library. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802)
{ "availability": "No subscription required", "binaries": [ { "firefox-locale-nl": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-kn": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-gl": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-sv": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-eo": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-fy": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-or": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-az": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-lt": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-hy": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-kk": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-km": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-uk": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-sr": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ca": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-is": "45.0+build2-0ubuntu0.14.04.1", "firefox-dbg": "45.0+build2-0ubuntu0.14.04.1", "firefox-testsuite": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ga": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-it": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ja": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-lg": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ms": "45.0+build2-0ubuntu0.14.04.1", "firefox-dev": "45.0+build2-0ubuntu0.14.04.1", "firefox-mozsymbols": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ko": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-hr": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-mai": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-nb": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-zh-hans": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-vi": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-he": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-sw": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-el": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-oc": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-xh": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-nn": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ar": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-csb": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-cs": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-gn": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-hsb": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-zu": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ro": "45.0+build2-0ubuntu0.14.04.1", "firefox-globalmenu": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-af": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-nso": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-sk": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-si": "45.0+build2-0ubuntu0.14.04.1", "firefox": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-cy": "45.0+build2-0ubuntu0.14.04.1", "firefox-dbgsym": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-fa": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-sq": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-en": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-tr": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-br": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-et": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ast": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-th": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-da": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-fi": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ku": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-mn": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ru": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-mk": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-bg": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-hu": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-gu": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-bn": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ml": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-an": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-be": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-eu": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-fr": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-pa": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-as": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-lv": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-mr": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-bs": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-te": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ta": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-ka": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-id": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-gd": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-hi": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-uz": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-pl": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-es": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-de": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-zh-hant": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-pt": "45.0+build2-0ubuntu0.14.04.1", "firefox-locale-sl": "45.0+build2-0ubuntu0.14.04.1" } ] }