Mozilla Foundation Security Advisory 2016-87
Security vulnerabilities fixed in Firefox 49.0.2
- Announced
- October 20, 2016
- Impact
- high
- Products
- Firefox
- Fixed in
-
- Firefox 49.0.2
#CVE-2016-5287: Crash in nsTArray_base<T>::SwapArrayElements
- Reporter
- Philipp
- Impact
- high
Description
A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49.
References
#CVE-2016-5288: Web content can read cache entries
- Reporter
- Developers at Cliqz.com
- Impact
- high
Description
A Cliqz.com developer demonstrated that web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49.