CVE-2017-7810: Buffer Overflow
Last updated 25 August 2025
Other sources
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
— Launchpad
Mozilla developers and community members Christoph Diehl, Jan de Mooij, Jason Kratzer, Randell Jesup, Tom Ritter, Tyson Smith, and Sebastian Hengst reported memory safety bugs present in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Mozilla developers and community members Christoph Diehl, Jan de Mooij, Jason Kratzer, Randell Jesup, Tom Ritter, Tyson Smith, and Sebastian Hengst reported memory safety bugs present in Firefox 55, Firefox ESR 52.3, and Thunderbird 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2017-7810?
CVE-2017-7810 has been rated as a high-severity vulnerability due to potential memory corruption leading to arbitrary code execution.
How do I fix CVE-2017-7810?
To mitigate CVE-2017-7810, update your Firefox to version 56 or later, or upgrade Firefox ESR to version 52.4 or later.
Which versions of Firefox are affected by CVE-2017-7810?
CVE-2017-7810 affects Firefox versions prior to 56 and Firefox ESR versions prior to 52.4.
Is Thunderbird also affected by CVE-2017-7810?
Yes, Thunderbird versions prior to 52.4 are affected by CVE-2017-7810 and should be updated.
Can CVE-2017-7810 be exploited remotely?
While CVE-2017-7810 exhibits evidence of memory corruption, successful exploitation would require significant effort and access to vulnerable systems.