CVE-2016-2824: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.

Affected products

  • Mozilla Firefox: version 45.1.0 only; version 45.1.1 only; up to and including 46.0.1
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2016-06-13. Last modified 2026-06-17.