CVE-2017-2534
published 2017-05-22CVE-2017-2534: An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Speech Framework" component. It allows attackers…
PriorityP434high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.78%
52.4th percentile
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Speech Framework" component. It allows attackers to conduct sandbox-escape attacks via a crafted app.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.12.4 | — |
| apple | macos_sierra_10.12.5_security_update_2017-002_el_capitan_and_security_update_201 | — | — |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2017-2534: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
vendor_apple·2017-05-15·CVSS 8.6
CVE-2017-2534 [HIGH] CVE-2017-2534: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
Apple Security Update: About the security content of macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
Product: macOS Sierra 10.12.5, Security Update 2017-002 El Capitan, and Security Update 2017-002 Yosemite
CVE: CVE-2017-2534
Component: Speech Framework
Impact: An application may be able to escape its sandbox
Description: An access issue was addressed through additional sandbox restrictions.
GHSA
GHSA-fxm5-m8r8-2rqj: An issue was discovered in certain Apple products
ghsa_unreviewed·2022-05-13
CVE-2017-2534 [HIGH] GHSA-fxm5-m8r8-2rqj: An issue was discovered in certain Apple products
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Speech Framework" component. It allows attackers to conduct sandbox-escape attacks via a crafted app.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7809 Mozilla: Use-after-free while deleting attached editor DOM node (MFSA 2017-19)
bugzilla·2017-08-09·CVSS 9.8
CVE-2017-7809 [CRITICAL] CVE-2017-7809 Mozilla: Use-after-free while deleting attached editor DOM node (MFSA 2017-19)
CVE-2017-7809 Mozilla: Use-after-free while deleting attached editor DOM node (MFSA 2017-19)
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7809
Discussion:
Acknowledgments:
Name: The Mozilla Project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.
Bugzilla
CVE-2017-7792 Mozilla: Buffer overflow viewing certificates with long OID (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 9.8
CVE-2017-7792 [CRITICAL] CVE-2017-7792 Mozilla: Buffer overflow viewing certificates with long OID (MFSA 2017-19)
CVE-2017-7792 Mozilla: Buffer overflow viewing certificates with long OID (MFSA 2017-19)
A buffer overflow with occur when viewing a certificate in the certificate manager if the certificate has a very long object identifier (OID). This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7792
Acknowledgements:
Name: the Mozilla project
Upstream: Fraser Tweedale
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://acces
Bugzilla
CVE-2017-7801 Mozilla: Use-after-free with marquee during window resizing
bugzilla·2017-08-08·CVSS 9.8
CVE-2017-7801 [CRITICAL] CVE-2017-7801 Mozilla: Use-after-free with marquee during window resizing
CVE-2017-7801 Mozilla: Use-after-free with marquee during window resizing
A use-after-free vulnerability while re-computing layout for a marquee element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7801
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.redha
Bugzilla
CVE-2017-7800 Mozilla: Use-after-free in WebSockets during disconnection (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 9.8
CVE-2017-7800 [CRITICAL] CVE-2017-7800 Mozilla: Use-after-free in WebSockets during disconnection (MFSA 2017-19)
CVE-2017-7800 Mozilla: Use-after-free in WebSockets during disconnection (MFSA 2017-19)
A use-after-free vulnerability in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7800
Acknowledgements:
Name: the Mozilla project
Upstream: Looben Yang
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.redhat.com/errat
Bugzilla
CVE-2017-7784 Mozilla: Use-after-free with image observers (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 9.8
CVE-2017-7784 [CRITICAL] CVE-2017-7784 Mozilla: Use-after-free with image observers (MFSA 2017-19)
CVE-2017-7784 Mozilla: Use-after-free with image observers (MFSA 2017-19)
A use-after-free vulnerability when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7784
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.redhat.com/errata/RHSA-2017:2534
Bugzilla
CVE-2017-7803 Mozilla: CSP directives improperly applied with sandbox flag in iframes (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 7.5
CVE-2017-7803 [HIGH] CVE-2017-7803 Mozilla: CSP directives improperly applied with sandbox flag in iframes (MFSA 2017-19)
CVE-2017-7803 Mozilla: CSP directives improperly applied with sandbox flag in iframes (MFSA 2017-19)
When a page’s content security policy (CSP) header contains a `sandbox` directive other directives are ignored. This results in the incorrect enforcement of CSP directives.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7803
Acknowledgements:
Name: the Mozilla project
Upstream: Rhys Enniks
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.redhat.co
Bugzilla
CVE-2017-7786 Mozilla: Buffer overflow while painting non-displayable SVG (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 9.8
CVE-2017-7786 [CRITICAL] CVE-2017-7786 Mozilla: Buffer overflow while painting non-displayable SVG (MFSA 2017-19)
CVE-2017-7786 Mozilla: Buffer overflow while painting non-displayable SVG (MFSA 2017-19)
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7786
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.redhat.com/errata/RHSA-2017:2534
---
Honestly impr
Bugzilla
CVE-2017-7807 Mozilla: Domain hijacking through appcache fallback (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 8.1
CVE-2017-7807 [HIGH] CVE-2017-7807 Mozilla: Domain hijacking through appcache fallback (MFSA 2017-19)
CVE-2017-7807 Mozilla: Domain hijacking through appcache fallback (MFSA 2017-19)
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7807
Acknowledgements:
Name: the Mozilla project
Upstream: Mathias Karlsson
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534
Bugzilla
CVE-2017-7753 Mozilla: Out-of-bounds read with cached style data and pseudo-elements (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 9.1
CVE-2017-7753 [CRITICAL] CVE-2017-7753 Mozilla: Out-of-bounds read with cached style data and pseudo-elements (MFSA 2017-19)
CVE-2017-7753 Mozilla: Out-of-bounds read with cached style data and pseudo-elements (MFSA 2017-19)
An out-of-bounds read when applying style rules to pseudo-elements like ::first-line using cached style data.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7753
Acknowledgements:
Name: the Mozilla project
Upstream: SkyLined
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.redhat.com/errata/RHSA-2017:2534
Bugzilla
CVE-2017-7787 Mozilla: Same-origin policy bypass with iframes through page reloads (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 7.5
CVE-2017-7787 [HIGH] CVE-2017-7787 Mozilla: Same-origin policy bypass with iframes through page reloads (MFSA 2017-19)
CVE-2017-7787 Mozilla: Same-origin policy bypass with iframes through page reloads (MFSA 2017-19)
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7787
Acknowledgements:
Name: the Mozilla project
Upstream: Oliver Wagner
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 ht
Bugzilla
CVE-2017-7785 Mozilla: Buffer overflow manipulating ARIA elements in DOM (MFSA 2017-19)
bugzilla·2017-08-08·CVSS 9.8
CVE-2017-7785 [CRITICAL] CVE-2017-7785 Mozilla: Buffer overflow manipulating ARIA elements in DOM (MFSA 2017-19)
CVE-2017-7785 Mozilla: Buffer overflow manipulating ARIA elements in DOM (MFSA 2017-19)
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-19/#CVE-2017-7785
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:2456 https://access.redhat.com/errata/RHSA-2017:2456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:2534 https://access.redhat.com/errata/RHSA-2017:2534
2017-05-22
Published