Aller au contenu
Appaloosa Scout

Vulnérabilité · NVD

CVE-2017-7765

HIGH 7.5

EN The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows displays before running executables downloaded from the Internet is not shown. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Vecteur d'attaque : Réseau Aucun privilège requis Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS 1.38% au-dessus de la médiane percentile 69.5%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (1)
Vendor Produit Versions
mozilla thunderbird
Toutes plateformes (wildcard)
<52.2.0
Voir sur NVD ↗ Advisory · bugzilla.mozilla.org Advisory · www.mozilla.org