E17-0fgk1
CVSS:
9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
120
Year:
2017
Description
This strike exploits a vulnerability that exists in Mozilla Firefox. Specifically, an integer overflow occurs in the ImageBitmap::Create function that can lead to an out of bounds memory read. A malicious attacker can call the createBitmapImage function with overly large values for arguments triggering this vulnerability. A successful attack can lead to a denial of service condition in the browser, or potentially lead to remote code execution.