6.1
CVSSv3

CVE-2017-7799

Published: 11/06/2018 Updated: 09/08/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is not under third-party control, making this difficult to exploit, but the vulnerability could possibly be used for a cross-site scripting (XSS) attack. This vulnerability affects Firefox < 55.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

USN-3391-1 introduced a regression in Firefox ...
This update provides compatible packages for Firefox 55 ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2017-18 Security vulnerabilities fixed in Firefox 55 Announced August 8, 2017 Impact critical Products Firefox Fixed in Firefox 55 ...
JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML" Data on this page is supplied by WebRTC usage and is not under third-party control, making this difficult to exploit, but the vulnerability could possibly be used for a cross-site scripting (XSS) attack This vulnerability affects Firefox &lt; 55 ...
A security issue has been found in Firefox &lt; 550 JavaScript in the about:webrtc page is not sanitized properly being being assigned to innerHTML Data on this page is supplied by WebRTC usage and is not under third-party control, making this difficult to exploit, but the vulnerability could possibly be used for a cross-site scripting (XSS) att ...