CVE-2017-7749: Use After Free
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7755
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-5470
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
Frequently Asked Questions
What is the severity of CVE-2017-7749?
CVE-2017-7749 is classified as a use-after-free vulnerability which has the potential to be exploited and causes crashes.
How do I fix CVE-2017-7749?
To fix CVE-2017-7749, update affected products like Firefox and Thunderbird to the latest versions specified by the vendor.
What products are affected by CVE-2017-7749?
CVE-2017-7749 affects Firefox, Firefox ESR, and Thunderbird versions below their respective fixed versions.
Can CVE-2017-7749 be exploited remotely?
Yes, an attacker could potentially exploit CVE-2017-7749 remotely through malicious webpages.
What are the consequences of exploiting CVE-2017-7749?
Exploiting CVE-2017-7749 could result in application crashes or the potential execution of arbitrary code.