5
CVSSv2

CVE-2017-5425

Published: 11/06/2018 Updated: 09/08/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

mozilla thunderbird

Vendor Advisories

Mozilla Foundation Security Advisory 2017-05 Security vulnerabilities fixed in Firefox 52 Announced March 7, 2017 Impact critical Products Firefox Fixed in Firefox 52 ...
Mozilla Foundation Security Advisory 2017-09 Security vulnerabilities fixed in - Thunderbird 52 Announced April 5, 2017 Impact critical Products Thunderbird Fixed in Thunderbird 52 ...