High severity8.8NVD Advisory· Published Jan 31, 2016· Updated May 6, 2026
CVE-2016-1935
CVE-2016-1935
Description
Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
Affected products
13cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=43.0.4
- cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.5.0:*:*:*:*:*:*:*
cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
19- lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-02/msg00003.htmlnvdThird Party Advisory
- www.mozilla.org/security/announce/2016/mfsa2016-03.htmlnvdVendor Advisory
- www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlnvdThird Party Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue Tracking
- lists.opensuse.org/opensuse-security-announce/2016-02/msg00010.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-02/msg00101.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-02/msg00105.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0071.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0258.htmlnvd
- www.debian.org/security/2016/dsa-3457nvd
- www.debian.org/security/2016/dsa-3491nvd
- www.securityfocus.com/bid/81952nvd
- www.securitytracker.com/id/1034825nvd
- www.ubuntu.com/usn/USN-2880-1nvd
- www.ubuntu.com/usn/USN-2880-2nvd
- www.ubuntu.com/usn/USN-2904-1nvd
- security.gentoo.org/glsa/201605-06nvd
News mentions
0No linked articles in our index yet.