CVE-2016-5253
published 2016-08-05CVE-2016-5253: The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path…
PriorityP419medium4.7CVSS 3.0
AVLACHPRLUINSUCNIHAN
EPSS
0.24%
15.8th percentile
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | <= 47.0.1 | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:N
vendor_debian4.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-5253: firefox - The Updater in Mozilla Firefox before 48.0 on Windows allows local users to writ...
vendor_debian·2016·CVSS 4.7
CVE-2016-5253 [MEDIUM] CVE-2016-5253: firefox - The Updater in Mozilla Firefox before 48.0 on Windows allows local users to writ...
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.
Scope: local
sid: resolved
GHSA
GHSA-rw7w-hjmw-gj5r: The Updater in Mozilla Firefox before 48
ghsa_unreviewed·2022-05-17
CVE-2016-5253 [MEDIUM] GHSA-rw7w-hjmw-gj5r: The Updater in Mozilla Firefox before 48
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.mozilla.org/security/announce/2016/mfsa2016-69.htmlhttp://www.securityfocus.com/bid/92260http://www.securitytracker.com/id/1036508https://bugzilla.mozilla.org/show_bug.cgi?id=1246944https://security.gentoo.org/glsa/201701-15http://www.mozilla.org/security/announce/2016/mfsa2016-69.htmlhttp://www.securityfocus.com/bid/92260http://www.securitytracker.com/id/1036508https://bugzilla.mozilla.org/show_bug.cgi?id=1246944https://security.gentoo.org/glsa/201701-15
2016-08-05
Published