Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.
References
Link Providers
http://hg.mozilla.org/releases/mozilla-release/rev/b208427885d3 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00089.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00091.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00006.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00007.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00008.html cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3510 cve-icon cve-icon
http://www.debian.org/security/2016/dsa-3520 cve-icon cve-icon
http://www.mozilla.org/security/announce/2016/mfsa2016-24.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html cve-icon cve-icon
http://www.securitytracker.com/id/1035215 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2917-1 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2917-2 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2917-3 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2934-1 cve-icon cve-icon
http://zerodayinitiative.com/advisories/ZDI-16-199/ cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=1249377 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2016-1961 cve-icon
https://security.gentoo.org/glsa/201605-06 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2016-1961 cve-icon
https://www.mozilla.org/security/announce/2016/mfsa2016-24.html cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2016-03-13T18:00:00

Updated: 2024-08-05T23:17:49.265Z

Reserved: 2016-01-20T00:00:00

Link: CVE-2016-1961

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2016-03-13T18:59:10.693

Modified: 2019-12-27T16:08:55.810

Link: CVE-2016-1961

cve-icon Redhat

Severity : Critical

Publid Date: 2016-03-08T00:00:00Z

Links: CVE-2016-1961 - Bugzilla