CVE-2017-7757: Use After Free
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5472
- CVE-2017-7749
- CVE-2017-7750
- CVE-2017-7751
- CVE-2017-7755
- CVE-2017-7752
- CVE-2017-7754
- CVE-2017-7756
- CVE-2017-7757
- CVE-2017-7778
- CVE-2017-7758
- CVE-2017-7763
- CVE-2017-7764
- CVE-2017-7765
- CVE-2017-5470
- CVE-2017-7759
- CVE-2017-7760
- CVE-2017-7761
- CVE-2017-7762
- CVE-2017-7766
- CVE-2017-7767
- CVE-2017-7768
- CVE-2017-7770
- CVE-2017-5471
Frequently Asked Questions
What is the severity of CVE-2017-7757?
CVE-2017-7757 has been classified as a potentially exploitable crash due to the use-after-free vulnerability.
How do I fix CVE-2017-7757?
To fix CVE-2017-7757, users should update to Firefox version 54 or later, Firefox ESR version 52.2 or later, or Thunderbird version 52.2 or later.
Which versions of Firefox are affected by CVE-2017-7757?
Affected versions of Firefox are those prior to version 54.
Is Thunderbird vulnerable to CVE-2017-7757?
Yes, Thunderbird versions prior to 52.2 are vulnerable to CVE-2017-7757.
What causes the vulnerability identified as CVE-2017-7757?
CVE-2017-7757 is caused by a use-after-free issue in IndexedDB when an object is destroyed while a method is still executing.