Back

CVE-2017-7778

CRITICAL

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Published: Jun 11, 2018 Modified: Jun 17, 2026
CWE-119 CWE-125 CWE-787

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (6)

Vendor Product Version
mozilla firefox * < 52.2.0
mozilla firefox * < 54.0
mozilla thunderbird * < 52.2.0
debian debian_linux 8.0
debian debian_linux 9.0
sil graphite2 * < 1.3.10

GitHub Security Advisory GHSA-w4p4-6xh7-fhf6

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads,...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.15%

Top 8% most likely to be exploited

Threat Score 40.7 / 100

Data Sources

NVD EPSS GitHub