CVE-2017-7794: Mozilla Firefox
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.
Affected products
- Mozilla Firefox: before 55.0 (fixed in 55.0)
Published 2018-06-11. Last modified 2026-06-17.