Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2017-5414

MEDIUM 5.5

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Attack vector : Local No user interaction
Show raw CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS 0.33% exploit very unlikely percentile 25.8%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (1)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
<52.0
View on NVD ↗ Advisory · bugzilla.mozilla.org Advisory · www.mozilla.org