CVE-2016-5271 PUBLISHED

The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.

EPSS 0.43% · 62.3th percentile

Risk Scores

EPSS Score
0.43%
62.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfirefox42.0+build2-0ubuntu1, 44.0+build3-0ubuntu2, 44.0.1+build1-0ubuntu1
Ubuntu:14.04:LTSfirefox35.0+build3-0ubuntu0.14.04.2, 35.0.1+build1-0ubuntu0.14.04.1, 36.0+build2-0ubuntu0.14.04.4

Timeline

References

Open in Interactive Console →