CVE-2018-5138
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. This could allow an attacker to spoof which page is actually loaded and in use. Note: this issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 59.
Una vulnerabilidad de suplantación puede ocurrir cuando un sitio malicioso con un nombre de dominio extremadamente largo se abre en una pestaña personalizada de Android (un panel de navegador dentro de otra aplicación) y el navegador predeterminado es Firefox para Android. Esto permite que un atacante suplante la página que está en realidad cargada y en uso. Nota: este problema sólo afecta a Firefox para Android. Las demás versiones y sistemas operativos no se ven afectados. Esta vulnerabilidad afecta a las versiones anteriores a la 59 de Firefox.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-03 CVE Reserved
- 2018-06-11 CVE Published
- 2023-11-02 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103386 | Third Party Advisory | |
http://www.securitytracker.com/id/1040514 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1432624 | 2018-08-08 | |
https://www.mozilla.org/security/advisories/mfsa2018-06 | 2018-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 59.0 Search vendor "Mozilla" for product "Firefox" and version " < 59.0" | - |
Affected
| in | Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | - | - |
Safe
|