VulnerabilityModified
CVE-2016-5253
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.
MEDIUM 4.7EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.24% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- http://www.mozilla.org/security/announce/2016/mfsa2016-69.htmlVendor Advisory
- http://www.securityfocus.com/bid/92260
- http://www.securitytracker.com/id/1036508
- https://bugzilla.mozilla.org/show_bug.cgi?id=1246944Issue Tracking, Permissions Required
- https://security.gentoo.org/glsa/201701-15
- http://www.mozilla.org/security/announce/2016/mfsa2016-69.htmlVendor Advisory
- http://www.securityfocus.com/bid/92260
- http://www.securitytracker.com/id/1036508
- https://bugzilla.mozilla.org/show_bug.cgi?id=1246944Issue Tracking, Permissions Required
- https://security.gentoo.org/glsa/201701-15
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.