CVE-2017-5470 addresses multiple memory safety bugs in Firefox, Firefox ESR, and Thunderbird, specifically affecting versions prior to Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. These vulnerabilities, categorized as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), could lead to memory corruption. With a CVSS score of 9.8 (CRITICAL), the vulnerability is network-exploitable with low attack complexity, potentially allowing for arbitrary code execution with high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV listed as No) and no public exploit code (Metasploit, Nuclei, ExploitDB are empty), the vulnerability has garnered significant community discussion with 11 mentions, indicating notable awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.