Описание
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 48.0+build2-0ubuntu1 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [48.0+build2-0ubuntu0.14.04.1]] |
| precise | released | 48.0+build2-0ubuntu0.12.04.1 |
| trusty | released | 48.0+build2-0ubuntu0.14.04.1 |
| trusty/esm | DNE | trusty was released [48.0+build2-0ubuntu0.14.04.1] |
| upstream | released | 48 |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | released | 48.0+build2-0ubuntu0.16.04.1 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected] |
| precise | not-affected | |
| trusty | not-affected | |
| trusty/esm | DNE | trusty was not-affected |
| upstream | not-affected | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| xenial | not-affected |
Показывать по
EPSS
4.3 Medium
CVSS2
4.3 Medium
CVSS3
Связанные уязвимости
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.
Mozilla Firefox before 48.0 allows remote attackers to spoof the locat ...
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.
Уязвимость браузера Firefox, позволяющая нарушителю подменить адресную строку
EPSS
4.3 Medium
CVSS2
4.3 Medium
CVSS3