CVE-2017-7813: Mozilla Firefox
High severity, CVSS 8.2. EPSS: 1.6% chance of exploitation in the next 30 days.
Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.
Affected products
- Mozilla Firefox: up to and including 55.0.3
Published 2018-06-11. Last modified 2026-06-17.