CVE-2017-5414: Mozilla Firefox

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Affected products

  • Mozilla Firefox: before 52.0 (fixed in 52.0)
  • Mozilla Thunderbird: before 52.0 (fixed in 52.0)

Published 2018-06-11. Last modified 2026-06-17.