CVE-2017-5415: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 12.6% chance of exploitation in the next 30 days.

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.

Affected products

  • Mozilla Firefox: before 52.0 (fixed in 52.0)

Published 2018-06-11. Last modified 2026-06-17.