Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-0246

Опубликовано: 07 янв. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

When using an invalid protocol scheme, an attacker could spoof the address bar. Note: This issue only affected Android operating systems. Other operating systems are unaffected. *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 134.0 (исключая)
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00139
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
ubuntu
12 месяцев назад

When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.

CVSS3: 5.4
redhat
12 месяцев назад

When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.

CVSS3: 6.5
debian
12 месяцев назад

When using an invalid protocol scheme, an attacker could spoof the add ...

CVSS3: 6.5
github
12 месяцев назад

When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.

CVSS3: 6.5
fstec
12 месяцев назад

Уязвимость браузера Mozilla Firefox, связанная с ошибками представления информации пользовательским интерфейсом, позволяющая нарушителю подменить адресную строку

EPSS

Процентиль: 35%
0.00139
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo