CVE-2017-5378 — Sensitive Information Exposure in Mozilla Firefox
Severity
7.5HIGHNVD
OSV9.8
EPSS
1.7%
top 17.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages10 packages
Also affects: Debian Linux 8.0, Enterprise Linux 5.0, 6.0, 7.0, 7.3, 7.4, 7.5