CVE-2017-7776: Mozilla Firefox

High severity, CVSS 8.1. EPSS: 2.8% chance of exploitation in the next 30 days.

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

Affected products

  • Mozilla Firefox: before 54.0 (fixed in 54.0)
  • Sil GRAPHITE2: before 1.3.10 (fixed in 1.3.10)

Published 2019-04-15. Last modified 2026-06-17.