CVE-2017-5387: Mozilla Firefox
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox < 51.
Affected products
- Mozilla Firefox: before 51.0 (fixed in 51.0)
Published 2018-06-11. Last modified 2026-06-17.