CVE-2017-7845
published 2018-06-11CVE-2017-7845: A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an…
PriorityP343high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
3.21%
86.8th percentile
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Thunderbird < 52.5.2, Firefox ESR < 52.5.2, and Firefox < 57.0.2.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 52.5.2 | 52.5.2 |
| mozilla | firefox | < 57.0.2 | 57.0.2 |
| mozilla | firefox | >= unspecified < 57.0.2 | 57.0.2 |
| mozilla | firefox_esr | >= unspecified < 52.5.2 | 52.5.2 |
| mozilla | thunderbird | < 52.5.2 | 52.5.2 |
| mozilla | thunderbird | >= unspecified < 52.5.2 | 52.5.2 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3rhj-p6qq-r5mv: A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content
ghsa_unreviewed·2022-05-14
CVE-2017-7845 [HIGH] CWE-119 GHSA-3rhj-p6qq-r5mv: A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Thunderbird < 52.5.2, Firefox ESR < 52.5.2, and Firefox < 57.0.2.
Debian
CVE-2017-7845: firefox - A buffer overflow occurs when drawing and validating elements using Direct 3D 9 ...
vendor_debian·2017·CVSS 8.8
CVE-2017-7845 [HIGH] CVE-2017-7845: firefox - A buffer overflow occurs when drawing and validating elements using Direct 3D 9 ...
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Thunderbird < 52.5.2, Firefox ESR < 52.5.2, and Firefox < 57.0.2.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/102115http://www.securitytracker.com/id/1040123https://bugzilla.mozilla.org/show_bug.cgi?id=1402372https://www.mozilla.org/security/advisories/mfsa2017-28/https://www.mozilla.org/security/advisories/mfsa2017-29/https://www.mozilla.org/security/advisories/mfsa2017-30/http://www.securityfocus.com/bid/102115http://www.securitytracker.com/id/1040123https://bugzilla.mozilla.org/show_bug.cgi?id=1402372https://www.mozilla.org/security/advisories/mfsa2017-28/https://www.mozilla.org/security/advisories/mfsa2017-29/https://www.mozilla.org/security/advisories/mfsa2017-30/
2018-06-11
Published