Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3559-1 | iceweasel security update |
EUVD |
EUVD-2016-3887 | Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table. |
Ubuntu USN |
USN-2936-1 | Firefox vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 22 Oct 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mozilla:firefox_esr:38.0.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.1.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.1.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.2.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.2.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.3.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.4.0:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.1.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.2.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.3.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.4.0:*:*:*:*:*:*:* |
| Vendors & Products |
Mozilla firefox Esr
|
Mon, 21 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mozilla:firefox_esr:38.5.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.6.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.6.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.7.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox_esr:38.7.1:*:*:*:*:*:*:* |
cpe:2.3:a:mozilla:firefox:38.5.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.5.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.6.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.6.1:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.7.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:38.7.1:*:*:*:*:*:*:* |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-05T23:32:21.311Z
Reserved: 2016-03-01T00:00:00
Link: CVE-2016-2814
No data.
Status : Deferred
Published: 2016-04-30T17:59:12.447
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-2814
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN