A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox | Nov 14, 2016 | Oct 21, 2016 |
| Mfsa2016 87 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 49.0.2 | Oct 25, 2016 | Oct 20, 2016 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox | Oct 26, 2016 | Oct 26, 2016 |
| Ubuntu | — | Upgrade firefox | Oct 27, 2016 | Oct 26, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub