AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2016-2838

HIGH · CVSS 8.8 EPSS 4.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-08-05 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2016-2838
Severity
HIGH
CVSS
8.8
EPSS
4.51%
Firefox

Original Filing — NVD Description

Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.