CVE-2017-7821 is a critical vulnerability affecting Firefox versions prior to 56, where WebExtensions can download and open non-executable files without explicit user interaction. This could lead to the exploitation of vulnerabilities in the programs handling those document types. With a CVSS score of 9.8 (CRITICAL), it presents a high-impact threat with network-based, low-complexity attacks potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 55.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 56CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.