CVE-2017-5415: Mozilla Firefox
Medium severity, CVSS 5.3. EPSS: 12.6% chance of exploitation in the next 30 days.
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
Affected products
- Mozilla Firefox: before 52.0 (fixed in 52.0)
Published 2018-06-11. Last modified 2026-06-17.