CVE-2017-7804 is a high-severity vulnerability affecting Mozilla Firefox, Firefox ESR, and Thunderbird on Windows operating systems, allowing malicious code to write arbitrary data to memory by re-purposing a destructor function. This flaw, with a CVSS score of 7.5, can bypass memory protections and lead to high integrity impact without requiring user interaction. While no public exploits, Metasploit modules, or Nuclei templates are available, and there is minimal community discussion, the vulnerability's nature suggests a potential for significant impact if exploited. It is not currently listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 52.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 55.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 52.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.