← Vulnerability feed

Vulnerability record · CVE-2016-1931 · published 31 January 2016

CVE-2016-1931: Mozilla firefox memory buffer overflow vulnerability

Mozilla · Firefox

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.

10.0 CVSS 3.0 Critical EPSS 5.7% · top 7.2% CWE-119 · Memory buffer overflow
10.0CVSS 3.0 base score, v2 10.0
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
42References
17 Jun 2026Last modified by NVD

Description

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html
http://www.mozilla.org/security/announce/2016/mfsa2016-01.html Vendor Advisory
http://www.securityfocus.com/bid/81953
http://www.securitytracker.com/id/1034825
http://www.ubuntu.com/usn/USN-2880-1
http://www.ubuntu.com/usn/USN-2880-2
https://bugzilla.mozilla.org/show_bug.cgi?id=1180064
https://bugzilla.mozilla.org/show_bug.cgi?id=1186973
https://bugzilla.mozilla.org/show_bug.cgi?id=1206675
https://bugzilla.mozilla.org/show_bug.cgi?id=1207298
https://bugzilla.mozilla.org/show_bug.cgi?id=1209358
https://bugzilla.mozilla.org/show_bug.cgi?id=1209365
https://bugzilla.mozilla.org/show_bug.cgi?id=1209366
https://bugzilla.mozilla.org/show_bug.cgi?id=1209368
https://bugzilla.mozilla.org/show_bug.cgi?id=1209546
https://bugzilla.mozilla.org/show_bug.cgi?id=1222015
https://bugzilla.mozilla.org/show_bug.cgi?id=1229825
https://bugzilla.mozilla.org/show_bug.cgi?id=1231121
https://bugzilla.mozilla.org/show_bug.cgi?id=1234576
https://security.gentoo.org/glsa/201605-06
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html
http://www.mozilla.org/security/announce/2016/mfsa2016-01.html Vendor Advisory
http://www.securityfocus.com/bid/81953
http://www.securitytracker.com/id/1034825
http://www.ubuntu.com/usn/USN-2880-1
http://www.ubuntu.com/usn/USN-2880-2
https://bugzilla.mozilla.org/show_bug.cgi?id=1180064
https://bugzilla.mozilla.org/show_bug.cgi?id=1186973
https://bugzilla.mozilla.org/show_bug.cgi?id=1206675
https://bugzilla.mozilla.org/show_bug.cgi?id=1207298
https://bugzilla.mozilla.org/show_bug.cgi?id=1209358
https://bugzilla.mozilla.org/show_bug.cgi?id=1209365
https://bugzilla.mozilla.org/show_bug.cgi?id=1209366
https://bugzilla.mozilla.org/show_bug.cgi?id=1209368
https://bugzilla.mozilla.org/show_bug.cgi?id=1209546
https://bugzilla.mozilla.org/show_bug.cgi?id=1222015
https://bugzilla.mozilla.org/show_bug.cgi?id=1229825
https://bugzilla.mozilla.org/show_bug.cgi?id=1231121

Track CVE-2016-1931 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed9.8CVE-2020-12641Roundcube Webmail OS command injection via image conversion path settingsRoundcube Webmail before 1.4.4 passes the im_convert_path and im_identify_path configuration settings to a shell without sanitization in rcube_image.…KEVEPSS 84%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2016-1931), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.