peter bassill · operator
$ cve CVE-2017-7824 JSON

CVE-2017-7824

9.8
CRITICAL · CVSS 3.0 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.6% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2018-06-11
Last modified2026-06-17

Affected (8)

VendorProduct
debiandebian linux
mozillafirefox
mozillathunderbird
redhatenterprise linux aus
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD