CVE-2017-5449: Input Validation
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5467
- CVE-2017-5430
- CVE-2017-5429
- CVE-2017-5448
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5450
- CVE-2017-5463
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
Frequently Asked Questions
What is the severity of CVE-2017-5449?
CVE-2017-5449 has been classified as a low severity vulnerability that may lead to a crash.
How do I fix CVE-2017-5449?
To fix CVE-2017-5449, upgrade to Mozilla Thunderbird 52.2, Firefox ESR 52.2, or Firefox 53 or later.
What systems are affected by CVE-2017-5449?
CVE-2017-5449 affects Mozilla Thunderbird versions prior to 52.2, Firefox ESR versions prior to 52.2, and Firefox versions prior to 53.
Can CVE-2017-5449 be exploited remotely?
CVE-2017-5449 involves a crash that could potentially be exploited through malicious web content.
Is CVE-2017-5449 specific to certain operating systems?
CVE-2017-5449 can affect multiple operating systems that run the vulnerable versions of Mozilla Thunderbird or Firefox.