CVE-2016-5275: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.

Affected products

  • Mozilla Firefox: up to and including 48.0.2

Published 2016-09-22. Last modified 2026-06-17.