CVE-2017-7814: Debian Linux

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Mozilla Firefox: before 52.4.0 (fixed in 52.4.0); before 56.0 (fixed in 56.0)
  • Mozilla Thunderbird: before 52.4.0 (fixed in 52.4.0)
  • Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.4 only
  • Red Hat Enterprise Linux Server Eus: version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only

Published 2018-06-11. Last modified 2026-06-17.