PoC Index

CVE-2017-7821

CRITICAL 9.8EPSS 2.0%

A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific user interaction for the file download and open actions. This could be used to trigger known vulnerabilities in the programs that handle those document types. This vulnerability affects Firefox < 56.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.95% chance of exploitation in the next 30 days, 79th percentile
Published
2018-06-11
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related