VDB
DEBIAN-CVE-2017-7814
DEBIAN-CVE-2017-7814
PUBLISHED
CVSS 7.800000190734863 HIGH
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Risk Scores
CVSS v3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | thunderbird | 0, 0, 0 |
| Debian:14 | firefox-esr | 0, 0, 0 |
| Debian:11 | firefox-esr | 0, 0, 0 |
| Debian:12 | firefox-esr | 0, 0, 0 |
| Debian:14 | thunderbird | 0, 0, 0 |
| Debian:13 | firefox-esr | 0, 0, 0 |
| Debian:13 | thunderbird | 0, 0, 0 |
| Debian:11 | thunderbird | 0, 0, 0 |
Timeline
- Jun 11, 2018 CVE Published
- Apr 28, 2026 CVE Updated