CVE-2017-5397: Mozilla Firefox
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.
Affected products
- Mozilla Firefox: before 51.0.3 (fixed in 51.0.3)
Published 2018-06-11. Last modified 2026-06-17.