CVE-2017-5378
7.5
HIGH
CVSS 3.1
EPSS 1.6%
Description
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
How to fix CVE-2017-5378
To remediate CVE-2017-5378, upgrade the affected package to a fixed version below.
- Debian/firefox-esr—upgrade to 45.7.0esr-1 or later
Is CVE-2017-5378 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 45.7.0esr-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |