Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2018 |
| Freebsd | — | Upgrade linux-seamonkeyUpgrade firefoxUpgrade libxulUpgrade linux-thunderbirdUpgrade thunderbirdUpgrade linux-firefoxUpgrade seamonkeyUpgrade firefox-esr | Jan 25, 2017 | Jan 24, 2017 |
| Mfsa2017 01 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 51.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox | Feb 2, 2017 | Jan 24, 2017 |
| Ubuntu | — | Upgrade firefox | Jan 28, 2017 | Jan 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub