Vulnerability Name: | CVE-2017-7770 (CCN-127251) | ||||||||||||||||
Assigned: | 2017-06-13 | ||||||||||||||||
Published: | 2017-06-13 | ||||||||||||||||
Updated: | 2018-08-13 | ||||||||||||||||
Summary: | A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing the location of an arbitrary website instead of the one loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox < 54. | ||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-7770 Source: BID Type: Third Party Advisory, VDB Entry 99049 Source: CCN Type: BID-99049 Mozilla Firefox for Android CVE-2017-7770 AddressBar URI Spoofing Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1038689 Source: CONFIRM Type: Issue Tracking, Vendor Advisory https://bugzilla.mozilla.org/show_bug.cgi?id=1317242 Source: XF Type: UNKNOWN firefox-cve20177770-spoofing(127251) Source: CCN Type: Mozilla Foundation Security Advisory 2017-15 Security vulnerabilities fixed in Firefox 54 Source: CCN Type: Mozilla Foundation Security Advisory 2017-16 Security vulnerabilities fixed in Firefox ESR 52.2 Source: CONFIRM Type: Vendor Advisory https://www.mozilla.org/security/advisories/mfsa2017-15/ | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |