CVE-2017-7836: Mozilla Firefox
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with Firefox's privileges. Note: This attack requires an attacker have local system access and only affects OS X and Linux. Windows systems are not affected. This vulnerability affects Firefox < 57.
Affected products
- Mozilla Firefox: up to and including 56.0.2
Published 2018-06-11. Last modified 2026-06-17.