Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade firefox | Jul 6, 2016 | Mar 9, 2016 |
| Debian | — | Upgrade firefox-esr | Jul 30, 2024 | Mar 13, 2016 |
| Freebsd | — | Upgrade linux-seamonkeyUpgrade firefoxUpgrade thunderbirdUpgrade firefox-esrUpgrade linux-thunderbirdUpgrade libxulUpgrade seamonkeyUpgrade linux-firefox | Dec 10, 2025 | Mar 8, 2016 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nspr.Upgrade dev-libs/nss. | Oct 30, 2017 | Mar 13, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade firefox | Nov 30, 2017 | Mar 13, 2016 |
| Mfsa2016 33 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 45.0 | Mar 10, 2016 | Mar 8, 2016 |
| Oracle_linux | — | Upgrade firefox | Mar 13, 2016 | Mar 13, 2016 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-common | Mar 14, 2016 | Mar 12, 2016 |
| Ubuntu | — | Upgrade firefox | Mar 13, 2016 | Mar 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub