← Retour aux CVEs
CVE-2017-5383
N/ADescription
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Details CVE
Score CVSS v3.1N/A
Publie6/11/2018
Derniere modification11/25/2025
Sourcenvd
Observations honeypot0
Produits affectes
debian:debian_linuxmozilla:firefoxmozilla:thunderbirdredhat:enterprise_linuxredhat:enterprise_linux_desktopredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_eusredhat:enterprise_linux_workstation
Faiblesses (CWE)
CWE-20
References
http://rhn.redhat.com/errata/RHSA-2017-0190.html(security@mozilla.org)
http://rhn.redhat.com/errata/RHSA-2017-0238.html(security@mozilla.org)
http://www.securityfocus.com/bid/95769(security@mozilla.org)
http://www.securitytracker.com/id/1037693(security@mozilla.org)
https://bugzilla.mozilla.org/show_bug.cgi?id=1323338(security@mozilla.org)
https://bugzilla.mozilla.org/show_bug.cgi?id=1324716(security@mozilla.org)
https://security.gentoo.org/glsa/201702-13(security@mozilla.org)
https://security.gentoo.org/glsa/201702-22(security@mozilla.org)
https://www.debian.org/security/2017/dsa-3771(security@mozilla.org)
https://www.debian.org/security/2017/dsa-3832(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2017-01/(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2017-02/(security@mozilla.org)
https://www.mozilla.org/security/advisories/mfsa2017-03/(security@mozilla.org)
http://rhn.redhat.com/errata/RHSA-2017-0190.html(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2017-0238.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/95769(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id/1037693(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=1323338(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.mozilla.org/show_bug.cgi?id=1324716(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201702-13(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201702-22(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2017/dsa-3771(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2017/dsa-3832(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2017-01/(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2017-02/(af854a3a-2127-422b-91ae-364da2661108)
https://www.mozilla.org/security/advisories/mfsa2017-03/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.