High severity8.8NVD Advisory· Published Aug 5, 2016· Updated May 6, 2026
CVE-2016-5264
CVE-2016-5264
Description
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- bugzilla.mozilla.org/show_bug.cginvdExploitIssue Tracking
- www.mozilla.org/security/announce/2016/mfsa2016-79.htmlnvdVendor Advisory
- www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-08/msg00029.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-1551.htmlnvd
- www.debian.org/security/2016/dsa-3640nvd
- www.securityfocus.com/bid/92258nvd
- www.securitytracker.com/id/1036508nvd
- www.ubuntu.com/usn/USN-3044-1nvd
- security.gentoo.org/glsa/201701-15nvd
News mentions
0No linked articles in our index yet.