CVE-2016-1972: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

Affected products

  • Mozilla Firefox: up to and including 44.0.2

Published 2016-03-13. Last modified 2026-06-17.