ZeroHour

CVE-2016-5258

PoC
CVSS 3.0
8.8 high
EPSS
3%p88
Published
()
Modified
Description

Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session.

Vendors
oraclemozilla
Products
linux, firefox
Weakness
CWE-416
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.