CVE-2017-7770
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing the location of an arbitrary website instead of the one loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox < 54.
Por medio de un mecanismo en el cual se carga una nueva pestaña mediante eventos de JavaScript, si se entra en modo de ventana completa, la barra de direcciones no se mostrará. Esto podría permitir que un sitio malicioso muestre una barra de direcciones suplantada que muestra la dirección de un sitio web arbitrario en lugar del que se ha cargado. Nota: este problema solo afecta a Firefox para Android. La versión de escritorio de Firefox no se ha visto afectada. La vulnerabilidad afecta a Firefox en versiones anteriores a la 54.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-12 CVE Reserved
- 2018-06-11 CVE Published
- 2023-11-02 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/99049 | Third Party Advisory | |
http://www.securitytracker.com/id/1038689 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1317242 | 2018-08-13 | |
https://www.mozilla.org/security/advisories/mfsa2017-15 | 2018-08-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 54.0 Search vendor "Mozilla" for product "Firefox" and version " < 54.0" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|