cvedb.io
CVE-2017-7787
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2018-06-11T21:29:09.233 · Last modified 2026-06-17T01:25:11.653

Summary

Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

Affected products

debian — debian_linux

Does this affect you?

Add your gear to cvedb and we'll alert you only when debian ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.