CVE-2017-7813 PUBLISHED

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.

EPSS 0.58% · 68.7th percentile

Risk Scores

EPSS Score
0.58%
68.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSfirefox0, 24.0+build1-0ubuntu1, 25.0+build3-0ubuntu0.13.10.1
Ubuntu:16.04:LTSfirefox0, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1
Ubuntu:18.04:LTSfirefox0
Ubuntu:18.04:LTSmozjs380, 38.8.0~repack1-0ubuntu1, 38.8.0~repack1-0ubuntu3

Timeline

References

Open in Interactive Console →