CVE-2016-1971: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

Affected products

  • Mozilla Firefox: up to and including 44.0.2

Published 2016-03-13. Last modified 2026-06-17.