1.9
CVSSv2

CVE-2017-5427

Published: 11/06/2018 Updated: 07/08/2018
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

USN-3216-1 introduced a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2017-05 Security vulnerabilities fixed in Firefox 52 Announced March 7, 2017 Impact critical Products Firefox Fixed in Firefox 52 ...
A non-existent chromemanifest file will attempt to be loaded during startup from the primary installation directory If a malicious user with local access puts chromemanifest and other referenced files in this directory, they will be loaded and activated during startup This could result in malicious software being added without consent or modifi ...