CVE-2017-7818: Use After Free
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. This results in a potentially exploitable crash.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7818?
CVE-2017-7818 is a use-after-free vulnerability that occurs when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM.
Which software is affected by CVE-2017-7818?
CVE-2017-7818 affects Firefox versions < 56, Firefox ESR versions < 52.4, and Thunderbird versions < 52.4.
What is the severity of CVE-2017-7818?
CVE-2017-7818 has a severity rating of 9.8 (Critical).
How can I fix CVE-2017-7818?
To fix CVE-2017-7818, it is recommended to update Firefox to version 56 or later, Firefox ESR to version 52.4 or later, and Thunderbird to version 52.4 or later.
Where can I find more information about CVE-2017-7818?
You can find more information about CVE-2017-7818 on Bugzilla (https://bugzilla.mozilla.org/show_bug.cgi?id=1363723), the Mozilla Security Advisories page (https://www.mozilla.org/en-US/security/advisories/mfsa2017-22/), and the SecurityFocus website (http://www.securityfocus.com/bid/101055).