CVE-2017-5403 PUBLISHED

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thunderbird < 52.

EPSS 0.52% · 66.5th percentile

Risk Scores

EPSS Score
0.52%
66.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfirefox0, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1
Ubuntu:14.04:LTSfirefox37.0.1+build1-0ubuntu0.14.04.1, 37.0.2+build1-0ubuntu0.14.04.1, 38.0+build3-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →