CVE-2017-5387: Low severity firefox vulnerability
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox < 51.
Other sources
The existence of a specifically requested local file can be found due to the double firing of the onerror when the source attribute on a <track> tag refers to a file that does not exist if the source page is loaded locally.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5375
- CVE-2017-5376
- CVE-2017-5377
- CVE-2017-5378
- CVE-2017-5379
- CVE-2017-5380
- CVE-2017-5390
- CVE-2017-5389
- CVE-2017-5396
- CVE-2017-5381
- CVE-2017-5382
- CVE-2017-5383
- CVE-2017-5384
- CVE-2017-5385
- CVE-2017-5386
- CVE-2017-5394
- CVE-2017-5391
- CVE-2017-5392
- CVE-2017-5393
- CVE-2017-5395
- CVE-2017-5387
- CVE-2017-5388
- CVE-2017-5374
- CVE-2017-5373
Frequently Asked Questions
What is the severity of CVE-2017-5387?
CVE-2017-5387 has a moderate severity level due to its potential for information disclosure.
How do I fix CVE-2017-5387?
To fix CVE-2017-5387, upgrade to Mozilla Firefox version 51 or later.
What versions of Firefox are affected by CVE-2017-5387?
CVE-2017-5387 affects all versions of Mozilla Firefox prior to version 51.
What is the main impact of CVE-2017-5387?
The main impact of CVE-2017-5387 is the unauthorized disclosure of local file existence.
Can I mitigate CVE-2017-5387 without an update?
There are no known effective workarounds to mitigate CVE-2017-5387 aside from updating Firefox.