CVE-2017-5404
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 17%
from disclosure to weapon0 days
Published on NVDJun 11
1st PoCMar 20
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
public PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/41660cve_referencewww.exploit-db.com/exploits/41660/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://rhn.redhat.com/errata/RHSA-2017-0459.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0461.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0498.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=1340138https://security.gentoo.org/glsa/201705-06https://security.gentoo.org/glsa/201705-07https://www.debian.org/security/2017/dsa-3805https://www.debian.org/security/2017/dsa-3832https://www.exploit-db.com/exploits/41660/https://www.mozilla.org/security/advisories/mfsa2017-05/https://www.mozilla.org/security/advisories/mfsa2017-06/https://www.mozilla.org/security/advisories/mfsa2017-07/