Critical severity9.8NVD Advisory· Published Jan 31, 2016· Updated May 6, 2026
CVE-2016-1946
CVE-2016-1946
Description
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.mozilla.org/security/announce/2016/mfsa2016-10.htmlnvdVendor Advisory
- hg.mozilla.org/mozilla-central/rev/2a57c0a0cf19nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.htmlnvd
- www.securityfocus.com/bid/81950nvd
- www.securitytracker.com/id/1034825nvd
- www.ubuntu.com/usn/USN-2880-1nvd
- www.ubuntu.com/usn/USN-2880-2nvd
- bugzilla.mozilla.org/show_bug.cginvd
- security.gentoo.org/glsa/201605-06nvd
News mentions
0No linked articles in our index yet.