AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-1960

HIGH · CVSS 8.8 EPSS 30.95% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-03-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2016-1960
Severity
HIGH
CVSS
8.8
EPSS
30.95%
Firefox

Original NVD Description

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.