An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2018 |
| Centos_linux | — | Upgrade firefoxUpgrade firefox-debuginfo | Mar 20, 2017 | Mar 17, 2017 |
| Freebsd | — | Upgrade firefox | Mar 18, 2017 | Mar 18, 2017 |
| Mfsa2017 08 | — | Upgrade to Mozilla Firefox ESR version 52.0.1Upgrade to Mozilla Firefox version 52.0.1 | Mar 20, 2017 | Mar 17, 2017 |
| Oracle_linux | — | Upgrade firefox | Mar 18, 2017 | Mar 17, 2017 |
| Redhat_linux | — | Upgrade firefoxUpgrade firefox-debuginfo | Mar 19, 2017 | Mar 17, 2017 |
| Suse | — | Upgrade mozillafirefoxUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-develUpgrade mozillafirefox-translations-common | Mar 21, 2017 | Mar 17, 2017 |
| Ubuntu | — | Upgrade firefox | Mar 21, 2017 | Mar 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub