Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mg37-fr9j-7cpg

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57.

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57.

EPSS

Процентиль: 76%
0.00981
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57.

CVSS3: 5.3
nvd
больше 7 лет назад

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57.

CVSS3: 5.3
debian
больше 7 лет назад

The combined, single character, version of the letter 'i' with any of ...

CVSS3: 5.3
fstec
больше 8 лет назад

Уязвимость браузера Mozilla Firefox, связанная с недостатком механизма проверки вводимых данных, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 76%
0.00981
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20