CVE-2017-5401 PUBLISHED

A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

EPSS 2.20% · 84.3th percentile

Risk Scores

EPSS Score
2.20%
84.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSthunderbird1:24.0+build1-0ubuntu1, 0, *
Ubuntu:16.04:LTSfirefox44.0+build3-0ubuntu2, 0, 42.0+build2-0ubuntu1
Ubuntu:16.04:LTSthunderbird0, 1:38.3.0+build1-0ubuntu2, 1:38.5.1+build2-0ubuntu1
Ubuntu:14.04:LTSfirefox40.0.3+build1-0ubuntu0.14.04.1, 40.0+build4-0ubuntu0.14.04.4, 40.0+build4-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →