CVE-2016-1951: Mozilla Netscape Portable Runtime

High severity, CVSS 8.6. EPSS: 3.1% chance of exploitation in the next 30 days.

Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.

Affected products

  • Mozilla Netscape Portable Runtime: up to and including 4.11

Published 2016-08-07. Last modified 2026-06-17.