Lucene search

K
cvelistMozillaCVELIST:CVE-2017-7836
HistoryJun 11, 2018 - 9:00 p.m.

CVE-2017-7836

2018-06-1121:00:00
mozilla
www.cve.org
6

AI Score

8

Confidence

High

EPSS

0.001

Percentile

25.1%

The “pingsender” executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox’s privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems are not affected. This vulnerability affects Firefox < 57.

CNA Affected

[
  {
    "product": "Firefox",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "57",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

8

Confidence

High

EPSS

0.001

Percentile

25.1%