CVE-2017-7763

CVSS v3.0 5.3 (Medium)
53% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.21 % (59th)
0.21% Progress
Affected Products 5
Advisories 7

Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2018-06-11 21:29:08
(6 years ago)
Updated Date
2018-08-14 12:40:11
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 54.0 version cpe:2.3:a:mozilla:firefox < 54.0
OR  
  Running on/with
  Mozilla Firefox Esr prior 52.2.0 version cpe:2.3:a:mozilla:firefox_esr < 52.2.0
OR  
  Running on/with
  Mozilla Thunderbird prior 52.2.0 version cpe:2.3:a:mozilla:thunderbird < 52.2.0
OR  
  Running on/with
  Apple Mac Os X cpe:2.3:o:apple:mac_os_x:-

Configuration #2

AND
    CPE23 From Up To
OR  
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
OR  
  Running on/with
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...