Vulnerability Name: | CVE-2017-7809 (CCN-130187) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2017-08-08 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2017-08-08 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2018-08-03 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
8.5 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-416 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-7809 Source: CCN Type: IBM Security Bulletin S1010746 (Scale Out Network Attached Storage) Multiple Mozilla Firefox vulnerability issues in IBM SONAS Source: BID Type: Third Party Advisory, VDB Entry 100203 Source: CCN Type: BID-100203 Mozilla Firefox and Firefox ESR CVE-2017-7809 Use After Free Remote Code Execution Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039124 Source: REDHAT Type: Third Party Advisory RHSA-2017:2456 Source: REDHAT Type: Third Party Advisory RHSA-2017:2534 Source: CONFIRM Type: Exploit, Issue Tracking, Vendor Advisory https://bugzilla.mozilla.org/show_bug.cgi?id=1380284 Source: XF Type: UNKNOWN firefox-cve20177809-code-exec(130187) Source: GENTOO Type: Third Party Advisory GLSA-201803-14 Source: DEBIAN Type: Third Party Advisory DSA-3928 Source: DEBIAN Type: Third Party Advisory DSA-3968 Source: CCN Type: Mozilla Foundation Security Advisory 2017-18 Security vulnerabilities fixed in Firefox 55 Source: CCN Type: Mozilla Foundation Security Advisory 2017-19 Security vulnerabilities fixed in Firefox ESR 52.3 Source: CONFIRM Type: Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2017-18/ Source: CONFIRM Type: Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2017-19/ Source: CONFIRM Type: Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2017-20/ | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
BACK |