CVE-2017-7752: Use After Free
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7755
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-5470
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
Frequently Asked Questions
What is the severity of CVE-2017-7752?
CVE-2017-7752 has a severity rating that indicates it could potentially lead to a crash and may be exploitable under certain conditions.
How do I fix CVE-2017-7752?
To fix CVE-2017-7752, upgrade to the latest version of affected software such as Firefox versions 118.0.2-1 or Firefox ESR versions 91.12.0esr-1~deb10u1.
What software is affected by CVE-2017-7752?
CVE-2017-7752 affects Mozilla Firefox, Firefox ESR, and Thunderbird, specifically older versions up to 54.0 and 52.2 respectively.
How can CVE-2017-7752 be exploited?
CVE-2017-7752 can be exploited through specific user interactions with the input method editor (IME) in some languages.
What impact does CVE-2017-7752 have on users?
The impact of CVE-2017-7752 may include application crashes, which could lead to data loss or expose users to potential attacks.