CVE-2016-5256: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Affected products

  • Mozilla Firefox: up to and including 48.0.2

Published 2016-09-22. Last modified 2026-06-17.