VDB

DEBIAN-CVE-2017-7814

DEBIAN-CVE-2017-7814 PUBLISHED CVSS 7.800000190734863 HIGH

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

Risk Scores

CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:12thunderbird0, 0, 0
Debian:14firefox-esr0, 0, 0
Debian:11firefox-esr0, 0, 0
Debian:12firefox-esr0, 0, 0
Debian:14thunderbird0, 0, 0
Debian:13firefox-esr0, 0, 0
Debian:13thunderbird0, 0, 0
Debian:11thunderbird0, 0, 0

Timeline

  • Jun 11, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›