[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-1951Date: (C)2016-08-25   (M)2023-12-22


Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.6CVSS Score : 7.5
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 4.7Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: LOWAvailability: PARTIAL
Integrity: LOW 
Availability: HIGH 
  
Reference:
SECTRACK-1036590
BID-92385
USN-3023-1
https://groups.google.com/forum/message/raw?msg=mozilla.dev.tech.nspr/dV4MyMsg6jw/hhWcXOgJDQAJ
https://bugzilla.mozilla.org/show_bug.cgi?id=1174015
https://hg.mozilla.org/projects/nspr/rev/96381e3aaae2

CPE    1
cpe:/a:mozilla:netscape_portable_runtime
CWE    1
CWE-190
OVAL    5
oval:org.secpod.oval:def:51601
oval:org.secpod.oval:def:703206
oval:org.secpod.oval:def:602640
oval:org.secpod.oval:def:703212
...

© SecPod Technologies