CVE-2017-7825

CVSS v3.0 5.3 (Medium)
53% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.30 % (70th)
0.30% Progress
Affected Products 5
Advisories 10

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

Weaknesses
CWE-20
Improper Input Validation
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2018-06-11 21:29:11
(6 years ago)
Updated Date
2018-08-06 16:32:16
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0

Configuration #2

AND
    CPE23 From Up To
OR  
  Mozilla Firefox prior 56.0 version cpe:2.3:a:mozilla:firefox < 56.0
OR  
  Running on/with
  Mozilla Firefox Esr prior 52.4.0 version cpe:2.3:a:mozilla:firefox_esr < 52.4.0
OR  
  Running on/with
  Mozilla Thunderbird prior 52.4.0 version cpe:2.3:a:mozilla:thunderbird < 52.4.0
OR  
  Running on/with
  Apple Mac Os X cpe:2.3:o:apple:mac_os_x
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...