CVE-2017-5387: Mozilla Firefox

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox < 51.

Affected products

  • Mozilla Firefox: before 51.0 (fixed in 51.0)

Published 2018-06-11. Last modified 2026-06-17.