CVE-2017-7845: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Thunderbird < 52.5.2, Firefox ESR < 52.5.2, and Firefox < 57.0.2.
Affected products
- Mozilla Firefox: before 52.5.2 (fixed in 52.5.2); before 57.0.2 (fixed in 57.0.2)
- Mozilla Thunderbird: before 52.5.2 (fixed in 52.5.2)
Published 2018-06-11. Last modified 2026-06-17.