CVE-2017-7812 PUBLISHED

If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to open. This can allow malicious web content to open a locally stored file through "file:" URLs. This vulnerability affects Firefox < 56.

EPSS 0.27% · 50.4th percentile

Risk Scores

EPSS Score
0.27%
50.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSfirefox0
Ubuntu:14.04:LTSfirefox24.0+build1-0ubuntu1, 25.0+build3-0ubuntu0.13.10.1, 28.0~b2+build1-0ubuntu2
Ubuntu:16.04:LTSfirefox41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1, 44.0+build3-0ubuntu2

Timeline

References

Open in Interactive Console →