Логотип exploitDog
bind:"GHSA-595h-pjc7-9xf6" OR bind:"CVE-2017-7805"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-595h-pjc7-9xf6" OR bind:"CVE-2017-7805"

Количество 11

Количество 11

github логотип

GHSA-595h-pjc7-9xf6

больше 3 лет назад

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-7805

больше 7 лет назад

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-7805

около 8 лет назад

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7805

больше 7 лет назад

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-7805

больше 7 лет назад

During TLS 1.2 exchanges, handshake hashes are generated which point t ...

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2017-2832

около 8 лет назад

ELSA-2017-2832: nss security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2018-00159

больше 8 лет назад

Уязвимость реализации протокола TLS 1.2 браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2017:2615-1

около 8 лет назад

Security update for Mozilla Firefox and NSS

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2872-2

около 8 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2872-1

около 8 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:2688-1

около 8 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-595h-pjc7-9xf6

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
4%
Низкий
больше 7 лет назад
redhat логотип
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
4%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
4%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point t ...

CVSS3: 7.5
4%
Низкий
больше 7 лет назад
oracle-oval логотип
ELSA-2017-2832

ELSA-2017-2832: nss security update (IMPORTANT)

около 8 лет назад
fstec логотип
BDU:2018-00159

Уязвимость реализации протокола TLS 1.2 браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
4%
Низкий
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:2615-1

Security update for Mozilla Firefox and NSS

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2872-2

Security update for MozillaFirefox, mozilla-nss

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2872-1

Security update for MozillaFirefox, mozilla-nss

около 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:2688-1

Security update for MozillaFirefox, mozilla-nss

около 8 лет назад

Уязвимостей на страницу