CVE-2017-5378 PUBLISHED

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

EPSS 1.70% · 82.2th percentile

Risk Scores

EPSS Score
1.70%
82.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird1:24.0+build1-0ubuntu1, 1:31.1.1+build1-0ubuntu0.14.04.1, 1:31.0+build1-0ubuntu0.14.04.1
Ubuntu:16.04:LTSthunderbird1:45.5.1+build1-0ubuntu0.16.04.1, 1:45.4.0+build1-0ubuntu0.16.04.1, 1:45.3.0+build1-0ubuntu0.16.04.2
Ubuntu:16.04:LTSfirefox49.0.2+build2-0ubuntu0.16.04.2, 0, 41.0.2+build2-0ubuntu1
Ubuntu:14.04:LTSfirefox42.0+build2-0ubuntu0.14.04.1, 41.0.2+build2-0ubuntu0.14.04.1, 41.0.1+build2-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →