Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5383

Опубликовано: 24 янв. 2017
Источник: redhat
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1416281Mozilla: Location bar spoofing with unicode characters (MFSA 2017-02)

EPSS

Процентиль: 85%
0.02444
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVSS3: 5.3
nvd
больше 7 лет назад

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVSS3: 5.3
debian
больше 7 лет назад

URLs containing certain unicode glyphs for alternative hyphens and quo ...

CVSS3: 5.3
github
больше 3 лет назад

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

oracle-oval
почти 9 лет назад

ELSA-2017-0238: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 85%
0.02444
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Уязвимость CVE-2017-5383