CVE-2017-7777: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

Affected products

  • Mozilla Firefox: before 54.0 (fixed in 54.0)
  • Sil GRAPHITE2: before 1.3.10 (fixed in 1.3.10)

Published 2019-04-15. Last modified 2026-06-17.