CVE-2016-2824
Last modified
CVE-2016-2824 is a vulnerability of currently unknown severity. The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.. EPSS estimates a 1.72% chance of exploitation in the next 30 days.
Description
The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 45.1.0 |
| Mozilla | Firefox | 45.1.1 |
| Opensuse | Leap | 42.1 |
| Opensuse | Opensuse | 13.1 |
| Opensuse | Opensuse | 13.2 |
| Mozilla | Firefox | <= 46.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2824?
How severe is CVE-2016-2824?
How do I fix CVE-2016-2824?
Are you affected by CVE-2016-2824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
