CVE-2016-2818: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 3.9% chance of exploitation in the next 30 days.

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Mozilla Firefox: version 45.1.0 only; version 45.1.1 only; up to and including 46.0.1
  • Novell Suse Linux Enterprise Desktop: version 12.0 only
  • Novell Suse Linux Enterprise Server: version 12.0 only
  • Novell Suse Linux Enterprise Software Development Kit: version 12.0 only
  • Novell Suse Package Hub For Suse Linux Enterprise: version 12 only
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 7.2 only
  • Red Hat Enterprise Linux For Power Big Endian: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux For Power Big Endian Eus: version 7.2 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0 only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 7.2 only
  • Red Hat Enterprise Linux For Scientific Computing: version 6.0 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.2 only
  • Red Hat Enterprise Linux Server Eus: version 7.2 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only; version 7.0 only

Published 2016-06-13. Last modified 2026-06-17.