WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-firefox-esr | Jun 11, 2018 | Jun 11, 2018 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jun 11, 2018 | |
| Centos_linux | — | centos-upgrade-firefoxcentos-upgrade-firefox-debuginfo | Jan 27, 2017 | Jan 24, 2017 |
| Debian | debian-upgrade-firefox-esr | Jan 27, 2017 | Jan 24, 2017 | |
| Freebsd | freebsd-upgrade-package-firefoxfreebsd-upgrade-package-seamonkeyfreebsd-upgrade-package-linux-seamonkeyfreebsd-upgrade-package-firefox-esrfreebsd-upgrade-package-linux-firefoxfreebsd-upgrade-package-libxulfreebsd-upgrade-package-thunderbirdfreebsd-upgrade-package-linux-thunderbird | Jan 25, 2017 | Jan 24, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | Oct 30, 2017 | Feb 20, 2017 | |
| Huawei Euleros 2_0_sp1 | huawei-euleros-2_0_sp1-upgrade-firefox | Oct 4, 2019 | Jun 11, 2018 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-firefox | Oct 4, 2019 | Jun 11, 2018 | |
| Mfsa2017 01 | mozilla-firefox-upgrade-51_0 | Jul 12, 2018 | Jun 11, 2018 | |
| Mfsa2017 02 | mozilla-firefox-esr-upgrade-45_7 | Jan 25, 2017 | Jan 24, 2017 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-mail-thunderbird-45-6-0-0-175-3-17-0-4-0oracle-solaris-11-3-upgrade-mail-thunderbird-plugin-thunderbird-lightning-45-6-0-0-175-3-17-0-4-0oracle-solaris-11-3-upgrade-web-browser-firefox-45-7-0-0-175-3-17-0-4-0oracle-solaris-11-3-upgrade-web-browser-firefox-plugin-firefox-java-45-7-0-0-175-3-17-0-4-0oracle-solaris-11-3-upgrade-web-data-firefox-bookmarks-45-7-0-0-175-3-17-0-4-0 | May 29, 2017 | May 29, 2017 | |
| Oracle_linux | — | oracle-linux-upgrade-firefox | Jan 26, 2017 | Jan 24, 2017 |
| Redhat_linux | — | redhat-upgrade-firefoxredhat-upgrade-firefox-debuginfo | Feb 3, 2017 | Jan 24, 2017 |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translationssuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-other | Feb 2, 2017 | Jan 24, 2017 |
| Ubuntu | ubuntu-upgrade-firefox | Jan 28, 2017 | Jan 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub