CVE-2017-7772: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

Affected products

  • Mozilla Firefox: before 54.0 (fixed in 54.0)
  • Sil GRAPHITE2: before 1.3.10 (fixed in 1.3.10)

Published 2019-04-12. Last modified 2026-06-17.