Critical severity9.8NVD Advisory· Published Jun 11, 2018· Updated Jun 17, 2026
CVE-2017-7809
CVE-2017-7809
Description
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweed
< 128.5.1-1.1+ 1 more
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 92.0-1.2
Patches
Vulnerability mechanics
References
11- bugzilla.mozilla.org/show_bug.cginvdExploitIssue TrackingVendor Advisory
- www.securityfocus.com/bid/100203nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039124nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2017:2456nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2017:2534nvdThird Party Advisory
- security.gentoo.org/glsa/201803-14nvdThird Party Advisory
- www.debian.org/security/2017/dsa-3928nvdThird Party Advisory
- www.debian.org/security/2017/dsa-3968nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2017-18/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2017-19/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2017-20/nvdVendor Advisory
News mentions
0No linked articles in our index yet.