ZeroHour

CVE-2016-5293

CVSS 3.0
5.5 medium
EPSS
<1%p27
Published
()
Modified
Description

When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.

Vendors
mozilladebian
Products
firefox, debian linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.