CVE-2016-1973: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.
Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors.
Affected products
- Mozilla Firefox: up to and including 44.0.2
- Oracle Linux: version 5.0 only; version 6 only; version 7 only
Published 2016-03-13. Last modified 2026-06-17.