CVE-2016-2819
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.
- Opensuse Leap
- = 42.1
- Opensuse
- = 13.1, 13.2
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 16.9% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2016-06-13
CVE-2016-2819 at NVD
7 known exploits for CVE-2016-2819
Proof-of-concept code and exploit modules indexed by Sploitus
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 46.0.1 ASM.JS JIT-Spray Remote Code Execution
Firefox 44.0.2 ASM.JS JIT-Spray Remote Code Execution