VDB
CVE-2017-5382
CVE-2017-5382
PUBLISHED
CVSS 7.5 HIGH
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal information not meant to be seen by web content. This vulnerability affects Firefox < 51.
EPSS 1.52% · 73.5th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.52%
73.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | firefox | 0, 24.0+build1-0ubuntu1, 25.0+build3-0ubuntu0.13.10.1 |
| Ubuntu:16.04:LTS | firefox | 0, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1 |
Timeline
- Jan 25, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Dec 29, 2021 EPSS Score
- Mar 2, 2022 EPSS Score
- May 4, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
- Nov 10, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 16, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-5382 third-party-advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2017-01/#CVE-2017-5382 third-party-advisory
- https://ubuntu.com/security/notices/USN-3175-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-5382 third-party-advisory