CVE-2017-5451
MEDIUMRedhat Enterprise Linux < 53.0 - Improper Input Validation
Title source: ruleDescription
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
References (8)
Core 8
Core References
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1106
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-12/
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-10/
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/97940
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2017-13/
Exploit, Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1273537
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1038320
Third Party Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1201
Scores
CVSS v3
4.3
EPSS
0.0055
EPSS Percentile
68.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-20
Status
published
Products (15)
mozilla/firefox
< 53.0
mozilla/thunderbird
< 52.1.0
redhat/enterprise_linux
6.0
redhat/enterprise_linux
7.0
redhat/enterprise_linux_desktop
6.0
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_server
6.0
redhat/enterprise_linux_server
7.0
redhat/enterprise_linux_server_aus
7.3
redhat/enterprise_linux_server_aus
7.4
... and 5 more
Published
Jun 11, 2018
Tracked Since
Feb 18, 2026