Lucene search

K
cvelistMozillaCVELIST:CVE-2017-7787
HistoryJun 11, 2018 - 9:00 p.m.

CVE-2017-7787

2018-06-1121:00:00
mozilla
www.cve.org
1

AI Score

7.8

Confidence

High

EPSS

0.004

Percentile

73.2%

Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

CNA Affected

[
  {
    "product": "Thunderbird",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "52.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Firefox ESR",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "52.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "Firefox",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "55",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]