CVE-2017-7778
published 2018-06-11CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.22%
91.6th percentile
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 54.0-1 (sid) | firefox 54.0-1 (sid) |
| debian | firefox-esr | < firefox 54.0-1 (sid) | firefox 54.0-1 (sid) |
| debian | graphite2 | < firefox 54.0-1 (sid) | firefox 54.0-1 (sid) |
| mozilla | firefox | < 52.2.0 | 52.2.0 |
| mozilla | firefox | < 54.0 | 54.0 |
| mozilla | firefox | >= 0 < 54.0+build3-0ubuntu0.14.04.1 | 54.0+build3-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 54.0+build3-0ubuntu0.16.04.1 | 54.0+build3-0ubuntu0.16.04.1 |
| mozilla | firefox | >= unspecified < 54 | 54 |
| mozilla | firefox_esr | >= unspecified < 52.2 | 52.2 |
| mozilla | thunderbird | < 52.2.0 | 52.2.0 |
| mozilla | thunderbird | >= 0 < 1:52.2.1+build1-0ubuntu0.14.04.1 | 1:52.2.1+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.2.1+build1-0ubuntu0.16.04.1 | 1:52.2.1+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 52.2 | 52.2 |
| sil | graphite2 | < 1.3.10 | 1.3.10 |
| sil | graphite2 | >= 0 < 1.3.10-1 | 1.3.10-1 |
| sil | graphite2 | >= 0 < 1.3.10-1 | 1.3.10-1 |
| sil | graphite2 | >= 0 < 1.3.10-1 | 1.3.10-1 |
| sil | graphite2 | >= 0 < 1.3.10-1 | 1.3.10-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
graphite2 vulnerabilities
vendor_ubuntu·2017-08-21
CVE-2017-7771 graphite2 vulnerabilities
Title: graphite2 vulnerabilities
Summary: graphite2 could be made to crash or run programs if it opened a specially
crafted font.
Holger Fuhrmannek and Tyson Smith discovered that graphite2 incorrectly
handled certain malformed fonts. If a user or automated system were tricked
into opening a specially-crafted font file, a remote attacker could use
this issue to cause graphite2 to crash, resulting in a denial of service,
or possibly execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart applications
using graphite2, such as LibreOffice, to make all the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2017-07-05·CVSS 9.8
CVE-2017-5470 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
read uninitialized memory, obtain sensitive information or execute
arbitrary code. (CVE-2017-5470, CVE-2017-5472,
CVE-2017-7749, CVE-2017-7750, CVE-2017-7751, CVE-2017-7752, CVE-2017-7754,
CVE-2017-7756, CVE-2017-7757, CVE-2017-7758, CVE-2017-7764)
Multiple security issues were discovered in the Graphite 2 library used
by Thunderbird. If a user were tricked in to opening a specially crafted
message, an attacker could potentially exploit these to cause a denial of
service, read u
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2017-06-15·CVSS 9.8
CVE-2017-5470 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, read uninitialized
memory, obtain sensitive information, spoof the addressbar contents, or
execute arbitrary code. (CVE-2017-5470, CVE-2017-5471, CVE-2017-5472,
CVE-2017-7749, CVE-2017-7750, CVE-2017-7751, CVE-2017-7752, CVE-2017-7754,
CVE-2017-7756, CVE-2017-7757, CVE-2017-7758, CVE-2017-7762, CVE-2017-7764)
Multiple security issues were discovered in the Graphite 2 library used by
Firefox. If a user were tricked in to opening a specially crafted website,
an attac
Red Hat
Mozilla: Vulnerabilities in the Graphite 2 library (MFSA 2017-16)
vendor_redhat·2017-06-14·CVSS 9.8
CVE-2017-7778 [CRITICAL] Mozilla: Vulnerabilities in the Graphite 2 library (MFSA 2017-16)
Mozilla: Vulnerabilities in the Graphite 2 library (MFSA 2017-16)
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Debian
CVE-2017-7778: firefox - A number of security vulnerabilities in the Graphite 2 library including out-of-...
vendor_debian·2017·CVSS 9.8
CVE-2017-7778 [CRITICAL] CVE-2017-7778: firefox - A number of security vulnerabilities in the Graphite 2 library including out-of-...
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
GHSA
GHSA-w4p4-6xh7-fhf6: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uniniti
ghsa_unreviewed·2022-05-14
CVE-2017-7778 [CRITICAL] CWE-119 GHSA-w4p4-6xh7-fhf6: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uniniti
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
OSV
CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uniniti
osv·2018-06-11·CVSS 9.8
CVE-2017-7778 [CRITICAL] CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uniniti
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
OSV
thunderbird vulnerabilities
osv·2017-07-05·CVSS 9.8
CVE-2017-5470 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
read uninitialized memory, obtain sensitive information or execute
arbitrary code. (CVE-2017-5470, CVE-2017-5472,
CVE-2017-7749, CVE-2017-7750, CVE-2017-7751, CVE-2017-7752, CVE-2017-7754,
CVE-2017-7756, CVE-2017-7757, CVE-2017-7758, CVE-2017-7764)
Multiple security issues were discovered in the Graphite 2 library used
by Thunderbird. If a user were tricked in to opening a specially crafted
message, an attacker could potentially exploit these to cause a denial of
service, read uninitialized memory, or execute arbitrary code.
(CVE-2017-7771, CVE-
OSV
firefox vulnerabilities
osv·2017-06-15·CVSS 9.8
CVE-2017-5470 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, read uninitialized
memory, obtain sensitive information, spoof the addressbar contents, or
execute arbitrary code. (CVE-2017-5470, CVE-2017-5471, CVE-2017-5472,
CVE-2017-7749, CVE-2017-7750, CVE-2017-7751, CVE-2017-7752, CVE-2017-7754,
CVE-2017-7756, CVE-2017-7757, CVE-2017-7758, CVE-2017-7762, CVE-2017-7764)
Multiple security issues were discovered in the Graphite 2 library used by
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service,
read uninitialized memory, or execute arbitrar
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7772 graphite2: heap-buffer-overflow write "lz4::decompress" (CVE-2017-7772)
bugzilla·2017-07-18·CVSS 8.8
CVE-2017-7772 [HIGH] CVE-2017-7772 graphite2: heap-buffer-overflow write "lz4::decompress" (CVE-2017-7772)
CVE-2017-7772 graphite2: heap-buffer-overflow write "lz4::decompress" (CVE-2017-7772)
A heap-based buffer overflow flaw related to "lz4::decompress" has been reported in graphite2. A remote attacker could exploit this issue to cause a crash, or, possibly, execute arbitrary code.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7775 graphite2: assertion error "size() > n"
bugzilla·2017-07-18·CVSS 9.8
CVE-2017-7775 [CRITICAL] CVE-2017-7775 graphite2: assertion error "size() > n"
CVE-2017-7775 graphite2: assertion error "size() > n"
An assertion error has been reported in graphite2. An attacker could possibly exploit this flaw to cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7774 graphite2: out of bounds read "graphite2::Silf::readGraphite"
bugzilla·2017-07-18·CVSS 9.1
CVE-2017-7774 [CRITICAL] CVE-2017-7774 graphite2: out of bounds read "graphite2::Silf::readGraphite"
CVE-2017-7774 graphite2: out of bounds read "graphite2::Silf::readGraphite"
An out of bounds read flaw related to "graphite2::Silf::readGraphite" has been reported in graphite2. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7773 graphite2: heap-buffer-overflow write "lz4::decompress" (src/Decompressor)
bugzilla·2017-07-18·CVSS 8.8
CVE-2017-7773 [HIGH] CVE-2017-7773 graphite2: heap-buffer-overflow write "lz4::decompress" (src/Decompressor)
CVE-2017-7773 graphite2: heap-buffer-overflow write "lz4::decompress" (src/Decompressor)
A heap-based buffer overflow flaw related to "lz4::decompress" (src/Decompressor) has been reported in graphite2. A remote attacker could exploit this issue to cause a crash, or, possibly, execute arbitrary code.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7777 graphite2: use of uninitialized memory "graphite2::GlyphCache::Loader::read_glyph"
bugzilla·2017-07-18·CVSS 8.8
CVE-2017-7777 [HIGH] CVE-2017-7777 graphite2: use of uninitialized memory "graphite2::GlyphCache::Loader::read_glyph"
CVE-2017-7777 graphite2: use of uninitialized memory "graphite2::GlyphCache::Loader::read_glyph"
The use of uninitialized memory related to "graphite2::GlyphCache::Loader::read_glyph" has been reported in graphite2. An attacker could possibly exploit this flaw to negatively impact the execution of an application
using graphite2 in unknown ways.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7776 graphite2: heap-buffer-overflow read "graphite2::Silf::getClassGlyph"
bugzilla·2017-07-18·CVSS 8.1
CVE-2017-7776 [HIGH] CVE-2017-7776 graphite2: heap-buffer-overflow read "graphite2::Silf::getClassGlyph"
CVE-2017-7776 graphite2: heap-buffer-overflow read "graphite2::Silf::getClassGlyph"
An out of bounds read flaw related to "graphite2::Silf::getClassGlyph" has been reported in graphite2. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7771 graphite2: out of bounds read in "graphite2::Pass::readPass"
bugzilla·2017-07-18·CVSS 8.1
CVE-2017-7771 [HIGH] CVE-2017-7771 graphite2: out of bounds read in "graphite2::Pass::readPass"
CVE-2017-7771 graphite2: out of bounds read in "graphite2::Pass::readPass"
An out of bounds read flaw related to "graphite2::Pass::readPass" has been reported in graphite2. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7778 Mozilla: Vulnerabilities in the Graphite 2 library (MFSA 2017-16)
bugzilla·2017-06-14·CVSS 8.1
CVE-2017-7778 [HIGH] CVE-2017-7778 Mozilla: Vulnerabilities in the Graphite 2 library (MFSA 2017-16)
CVE-2017-7778 Mozilla: Vulnerabilities in the Graphite 2 library (MFSA 2017-16)
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10.
Please note: Previously, this bug contained a collection of various CVEs. Some CVEs have been moved into separate bugs:
CVE-2017-7771: bug #1472212
CVE-2017-7772: bug #1472213
CVE-2017-7773: bug #1472215
CVE-2017-7774: bug #1472219
CVE-2017-7775: bug #1472221
CVE-2017-7776: bug #1472223
CVE-2017-7777: bug #1472225
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
Acknowledgements:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Ty
arXiv
Using a Collated Cybersecurity Dataset for Machine Learning and Artificial Intelligence
arxiv_fulltext·2021-08-05
Using a Collated Cybersecurity Dataset for Machine Learning and Artificial Intelligence
Using a Collated Cybersecurity Dataset for Machine Learning and Artificial Intelligence
Erik Hemberg
MIT CSAIL
32 Vassar Street
Cambridge
United States of America
[email protected]
Una-May O'Reilly
MIT CSAIL
32 Vassar Street
Cambridge
United States of America
[email protected]
CAPEC
CVE
CWE
## Abstract
Artificial Intelligence (AI) and Machine Learning (ML) algorithms can support the span of indicator-level, e.g. anomaly detection, to behavioral level cyber security modeling and inference. This contribution is based on a dataset named which is amalgamated from public threat and vulnerability behavioral sources. We demonstrate how can support prediction of related threat techniques and attack patterns. We also discuss other AI and ML uses of to exploit its behavioral knowle
arXiv
Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
arxiv_fulltext·2021-02-10·CVSS 8.8
CVE-2017-11882 [HIGH] Linking Threat Tactics, Techniques, and Patterns with Defensive Weaknesses, Vulnerabilities and Affected Platform Configurations for Cyber Hunting
Top 10 Most Exploited Vulnerabilities 2016-2019
(https://us-cert.cisa.gov/ncas/alerts/aa20-133a)
.83fcdec8a329824466f140a2e6cdfeec473a9ee2 .0
longtable[]@lllllll@
& CVSS Score & Number of Tactics & Number of Techniques &
Number of CAPECs & Number of CWEs & Number of CPEs
CVE-2017-11882 & 8.55 & 0 & 0 & 12 & 1 & 4
CVE-2017-0199 & 8.55 & 0 & 0 & 0 & 0 & 9
CVE-2017-5638 & 10.0 & 1 & 3 & 51 & 1 & 53
CVE-2012-0158 & 9.3 & 0 & 0 & 3 & 1 & 29
CVE-2019-0604 & 8.65 & 1 & 3 & 51 & 1 & 4
CVE-2017-0143 & 0.0 (not listed in BRON but NVD says high severity)
& 0 & 0 & 0 & 0 & 0
CVE-2018-4878 & 8.65 & 0 & 0 & 0 & 1 & 3
CVE-2017-8759 & 8.55 & 1 & 3 & 51 & 1 & 8
CVE-2015-1641 & 9.3 & 0 & 0 & 0 & 1 & 11
CVE-2018-7600 & 8.65 & 1 & 3 & 51 & 1 & 4
longtable
4 out of Top 10 Vulnerabilities share the follow
http://www.securityfocus.com/bid/99057http://www.securitytracker.com/id/1038689https://access.redhat.com/errata/RHSA-2017:1440https://access.redhat.com/errata/RHSA-2017:1561https://access.redhat.com/errata/RHSA-2017:1793https://bugzilla.mozilla.org/show_bug.cgi?id=1349310https://bugzilla.mozilla.org/show_bug.cgi?id=1350047https://bugzilla.mozilla.org/show_bug.cgi?id=1352745https://bugzilla.mozilla.org/show_bug.cgi?id=1352747https://bugzilla.mozilla.org/show_bug.cgi?id=1355174https://bugzilla.mozilla.org/show_bug.cgi?id=1355182https://bugzilla.mozilla.org/show_bug.cgi?id=1356607https://bugzilla.mozilla.org/show_bug.cgi?id=1358551https://security.gentoo.org/glsa/201710-13https://www.debian.org/security/2017/dsa-3881https://www.debian.org/security/2017/dsa-3894https://www.debian.org/security/2017/dsa-3918https://www.mozilla.org/security/advisories/mfsa2017-15/https://www.mozilla.org/security/advisories/mfsa2017-16/https://www.mozilla.org/security/advisories/mfsa2017-17/http://www.securityfocus.com/bid/99057http://www.securitytracker.com/id/1038689https://access.redhat.com/errata/RHSA-2017:1440https://access.redhat.com/errata/RHSA-2017:1561https://access.redhat.com/errata/RHSA-2017:1793https://bugzilla.mozilla.org/show_bug.cgi?id=1349310https://bugzilla.mozilla.org/show_bug.cgi?id=1350047https://bugzilla.mozilla.org/show_bug.cgi?id=1352745https://bugzilla.mozilla.org/show_bug.cgi?id=1352747https://bugzilla.mozilla.org/show_bug.cgi?id=1355174https://bugzilla.mozilla.org/show_bug.cgi?id=1355182https://bugzilla.mozilla.org/show_bug.cgi?id=1356607https://bugzilla.mozilla.org/show_bug.cgi?id=1358551https://security.gentoo.org/glsa/201710-13https://www.debian.org/security/2017/dsa-3881https://www.debian.org/security/2017/dsa-3894https://www.debian.org/security/2017/dsa-3918https://www.mozilla.org/security/advisories/mfsa2017-15/https://www.mozilla.org/security/advisories/mfsa2017-16/https://www.mozilla.org/security/advisories/mfsa2017-17/
2018-06-11
Published