CVE-2016-5261

Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 and Firefox ESR < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets that trigger incorrect buffer-resize operations during buffering.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-08-05 01:59

Updated : 2024-02-28 15:21


NVD link : CVE-2016-5261

Mitre link : CVE-2016-5261

CVE.ORG link : CVE-2016-5261


JSON object : View

Products Affected

mozilla

  • firefox
CWE
CWE-190

Integer Overflow or Wraparound