CVE-2017-5373 describes memory safety bugs in Firefox 50.1, Firefox ESR 45.6, and earlier versions of Firefox, Firefox ESR, and Thunderbird. These bugs could lead to memory corruption, potentially allowing an attacker to execute arbitrary code. With a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low complexity, enabling full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability received notable media coverage and community discussion at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 45.7.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 51.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 45.7.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.