Join the Mozilla’s Test Days event from Dec 2–8 to test the new Firefox address bar on Firefox Beta 134 and get a chance to win Mozilla swag vouchers! 🎁

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Why do I get a vunerability advice with Firefox

  • 5 replies
  • 1 has this problem
  • 13 views
  • Last reply by Rlpellet

more options

After I do a Kaspersky vulnerability scan I get the following detail advice: C:Program Files\Mozilla Firefox\firefox exe.

I have upadated to the latest version 50.0.1 and the vulnerability still appears. Is this dangerous? Do I disregard? How to fix?

After I do a Kaspersky vulnerability scan I get the following detail advice: C:Program Files\Mozilla Firefox\firefox exe. I have upadated to the latest version 50.0.1 and the vulnerability still appears. Is this dangerous? Do I disregard? How to fix?

Chosen solution

hi Rlpellet, i think the result is correct, as there is a general vulnerability in firefox that was brought to mozilla's attention a short while ago: https://www.wordfence.com/blog/2016/11/emergency-bulletin-firefox-0-day-wild/ a fix for it is in development and testing right now and will hopefully pushed out to users as an update to firefox 50.0.2 later today.

a workaround in the meantime would be to disable javascript in the browser by default, then websites will be unable to exploit the vulnerability. you could use an addon like noscript for that purpose: https://addons.mozilla.org/firefox/addon/noscript/

Read this answer in context 👍 2

All Replies (5)

more options

Chosen Solution

hi Rlpellet, i think the result is correct, as there is a general vulnerability in firefox that was brought to mozilla's attention a short while ago: https://www.wordfence.com/blog/2016/11/emergency-bulletin-firefox-0-day-wild/ a fix for it is in development and testing right now and will hopefully pushed out to users as an update to firefox 50.0.2 later today.

a workaround in the meantime would be to disable javascript in the browser by default, then websites will be unable to exploit the vulnerability. you could use an addon like noscript for that purpose: https://addons.mozilla.org/firefox/addon/noscript/

more options

Would about:config changing javascript.enabled = false work for this?

more options

yes, but the the fix is ready by now - users can update firefox by going to the firefox menu ≡ > (?) help > about firefox panel.

more options

Thank you.

more options

thank you all for your response