CVE-2017-7827
UnknownEPSS 2.74%
Last modified
CVE-2017-7827 is a vulnerability of currently unknown severity. Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. EPSS estimates a 2.74% chance of exploitation in the next 30 days.
Description
Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 56.0.2 |
References
- http://www.securityfocus.com/bid/101832Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039803Third Party Advisory, VDB Entry
- https://www.mozilla.org/security/advisories/mfsa2017-24/Vendor Advisory
- http://www.securityfocus.com/bid/101832Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039803Third Party Advisory, VDB Entry
- https://www.mozilla.org/security/advisories/mfsa2017-24/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7827?
Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57.
How severe is CVE-2017-7827?
Severity scoring for CVE-2017-7827 is pending analysis. The EPSS model estimates a 2.74% probability of exploitation in the next 30 days.
How do I fix CVE-2017-7827?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7821A vulnerability where WebExtensions can download and attempt…
- CVE-2017-7822The AES-GCM implementation in WebCrypto API accepts 0-length…
- CVE-2017-7823The content security policy (CSP) "sandbox" directive did no…
- CVE-2017-7824A buffer overflow occurs when drawing and validating element…
- CVE-2017-7825Several fonts on OS X display some Tibetan and Arabic charac…
- CVE-2017-7826Memory safety bugs were reported in Firefox 56 and Firefox E…
- CVE-2017-7828A use-after-free vulnerability can occur when flushing and r…
- CVE-2017-7829It is possible to spoof the sender's email address and displ…
- CVE-2017-7830The Resource Timing API incorrectly revealed navigations in …
- CVE-2017-7831A vulnerability where the security wrapper does not deny acc…
- CVE-2017-7832The combined, single character, version of the letter 'i' wi…
- CVE-2017-7833Some Arabic and Indic vowel marker characters can be combine…
Are you affected by CVE-2017-7827?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
