CVE-2016-5294: Mozilla Firefox

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

Affected products

  • Mozilla Firefox: before 45.5.0 (fixed in 45.5.0); before 50.0 (fixed in 50.0)
  • Mozilla Thunderbird: before 45.5.0 (fixed in 45.5.0)

Published 2018-06-11. Last modified 2026-06-17.