CVE-2017-5404
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
- Debian Debian Linux
- = 9.0
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 17.3% (97th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2018-06-11
CVE-2017-5404 at NVD
3 known exploits for CVE-2017-5404
Proof-of-concept code and exploit modules indexed by Sploitus