cbcvebase.
CVE-2016-5253
published 2016-08-05

CVE-2016-5253: The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path…

PriorityP419medium4.7CVSS 3.0
AVLACHPRLUINSUCNIHAN
EPSS
0.24%
15.8th percentile
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
mozillafirefox<= 47.0.1

CVSS provenance

nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:N
vendor_debian4.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.