100401vdb entry
http://www.securityfocus.com/bid/100401 CVE-2017-7783
HIGH
Mozilla Firefox < 55 - Denial of Service
Record summary
CVE-2017-7783 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FirefoxBrowse Mozilla / Firefox | CVE List | Before 55 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox < 55 - Denial of ServiceExploitDB exploitby Amit SangraNot analyzed1 file
References
61039124vdb entry
http://www.securitytracker.com/id/1039124 bugzilla.mozilla.orgConfirmation
https://bugzilla.mozilla.org/show_bug.cgi?id=1360842 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-7783 43020exploit
https://www.exploit-db.com/exploits/43020 mozilla.orgConfirmation
https://www.mozilla.org/security/advisories/mfsa2017-18