Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-799g-3g44-3g9m

Опубликовано: 01 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.

EPSS

Процентиль: 31%
0.00112
Низкий

7.3 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.

CVSS3: 5.4
redhat
4 месяца назад

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.

CVSS3: 7.3
nvd
4 месяца назад

A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.

CVSS3: 7.3
debian
4 месяца назад

A crafted URL containing specific Unicode characters could have hidden ...

CVSS3: 7.3
fstec
4 месяца назад

Уязвимость браузера Mozilla Firefox и почтового клиента Thunderbird, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 31%
0.00112
Низкий

7.3 High

CVSS3

Дефекты

CWE-290