CVE-2017-5375
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
- Affected products
- Alt Linux, Centos, Firefox, Firefox Esr, Red Hat, Suse, Thunderbird, Ubuntu
- Redhat Enterprise Linux Desktop
- = 5.0, 6.0, 7.0
- Redhat Enterprise Linux Server
- = 5.0, 6.0, 7.0
- Redhat Enterprise Linux Workstation
- = 5.0, 6.0, 7.0
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 19.7% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2018-06-11
CVE-2017-5375 at NVD
12 known exploits for CVE-2017-5375
Proof-of-concept code and exploit modules indexed by Sploitus
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
Firefox 46.0.1 ASM.JS JIT-Spray Remote Code Execution
Firefox 44.0.2 ASM.JS JIT-Spray Remote Code Execution
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution Exploit
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution
Firefox 50.0.1 ASM.JS JIT-Spray Remote Code Execution