CVE-2017-7782

CVSS v3.0 5.3 (Medium)
53% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.51 % (77th)
0.51% Progress
Affected Products 4
Advisories 7

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

Weaknesses
CWE-269
Improper Privilege Management
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2018-06-11 21:29:08
(6 years ago)
Updated Date
2019-10-03 00:03:26
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 55.0 version cpe:2.3:a:mozilla:firefox < 55.0
OR  
  Running on/with
  Mozilla Firefox Esr prior 52.3.0 version cpe:2.3:a:mozilla:firefox_esr < 52.3.0
OR  
  Running on/with
  Mozilla Thunderbird prior 52.3.0 version cpe:2.3:a:mozilla:thunderbird < 52.3.0
OR  
  Running on/with
  Microsoft Windows cpe:2.3:o:microsoft:windows:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...