[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2016-2837Date: (C)2016-08-25   (M)2024-03-27


Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing a malformed video and leveraging a Gecko Media Plugin (GMP) sandbox bypass.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.3CVSS Score : 6.8
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 3.4Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: LOWAvailability: PARTIAL
Integrity: LOW 
Availability: LOW 
  
Reference:
SECTRACK-1036508
BID-92258
DSA-3640
GLSA-201701-15
RHSA-2016:1551
USN-3044-1
http://www.mozilla.org/security/announce/2016/mfsa2016-77.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
http://www.zerodayinitiative.com/advisories/ZDI-16-673
https://bugzilla.mozilla.org/show_bug.cgi?id=1274637
openSUSE-SU-2016:1964
openSUSE-SU-2016:2026

CPE    2
cpe:/o:oracle:linux:6.0
cpe:/o:oracle:linux:7.0
CWE    1
CWE-119
OVAL    16
oval:org.secpod.oval:def:36634
oval:org.secpod.oval:def:36633
oval:org.secpod.oval:def:89045348
oval:org.secpod.oval:def:203981
...

© SecPod Technologies