CVE-2016-5253: Mozilla Firefox
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.
Affected products
- Mozilla Firefox: up to and including 47.0.1
Published 2016-08-05. Last modified 2026-06-17.