Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-thunderbirdUpgrade linux-firefoxUpgrade libxulUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade firefoxUpgrade seamonkey | Dec 10, 2025 | Feb 1, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/nss.Upgrade www-client/firefox.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox-bin.Upgrade dev-libs/nspr.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Jan 31, 2016 |
| Mfsa2016 01 | — | Upgrade to Mozilla Firefox ESR version 38.6Upgrade to Mozilla Firefox version 44.0Upgrade to the latest version of Mozilla Firefox | Jan 29, 2016 | Jan 26, 2016 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 38.6 | Feb 17, 2016 | Jan 31, 2016 |
| Oracle Solaris | — | Upgrade developer/yasm to version 1.3.0-0.175.3.14.0.2.0 on Solaris 11.3Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade web/browser/firefox to version 45.4.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade web/data/firefox-bookmarks to version 45.4.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade mail/thunderbird to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3 | May 29, 2017 | Jan 31, 2016 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-devel | Feb 2, 2016 | Jan 31, 2016 |
| Ubuntu | — | Upgrade firefox | Feb 2, 2016 | Jan 31, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub