VulnerabilityModified
CVE-2017-7820
The "instanceof" operator can bypass the Xray wrapper mechanism.
MEDIUM 5.3EPSS 1.19%
Does this matter?
Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.
Description
The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content can provide its own result for that operator, possibly tricking the browser or extension into mishandling the element. This vulnerability affects Firefox < 56.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/101057Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039465Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1378207Exploit, Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2017-21/Vendor Advisory
- http://www.securityfocus.com/bid/101057Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039465Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1378207Exploit, Issue Tracking
- https://www.mozilla.org/security/advisories/mfsa2017-21/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.