CVE-2017-7837: Input Validation
Last updated 24 July 2024
Other sources
SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57.
— Launchpad
SVG loaded through <img> tags can use <meta> tags within the SVG data to set cookies for that page.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7837?
CVE-2017-7837 is a vulnerability that allows SVG loaded through <img> tags to set cookies using <meta> tags within the SVG data.
Which software is affected by CVE-2017-7837?
The vulnerability affects Firefox versions below 57.
What is the severity of CVE-2017-7837?
The severity of CVE-2017-7837 is medium with a severity score of 5.3.
How can I fix CVE-2017-7837?
To fix CVE-2017-7837, update your Firefox browser to version 57 or higher.
Where can I find more information about CVE-2017-7837?
You can find more information about CVE-2017-7837 on the following references: - [Bugzilla Mozilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1325923) - [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2017-24/) - [SecurityFocus](http://www.securityfocus.com/bid/101832)