CVE-2017-5428
9.8
CRITICAL · CVSS 3.0 · EPSS 3.2% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.25% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-06-11 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | firefox esr |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux workstation |
References
- http://rhn.redhat.com/errata/RHSA-2017-0558.html
- http://www.securityfocus.com/bid/96959
- http://www.securitytracker.com/id/1038060
- https://bugzilla.mozilla.org/show_bug.cgi?id=1348168
- https://www.mozilla.org/security/advisories/mfsa2017-08/
- http://rhn.redhat.com/errata/RHSA-2017-0558.html
- http://www.securityfocus.com/bid/96959
- http://www.securitytracker.com/id/1038060
- https://bugzilla.mozilla.org/show_bug.cgi?id=1348168
- https://www.mozilla.org/security/advisories/mfsa2017-08/
→ the Explorer · watch your stack · NVD