CVE-2017-5415
published 2018-06-11CVE-2017-5415: An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further…
PriorityP343medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EXPLOIT
EPSS
12.59%
95.7th percentile
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 52.0-1 (sid) | firefox 52.0-1 (sid) |
| mozilla | firefox | < 52.0 | 52.0 |
| mozilla | firefox | >= 0 < 52.0+build2-0ubuntu0.14.04.1 | 52.0+build2-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 52.0.2+build1-0ubuntu0.14.04.1 | 52.0.2+build1-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 52.0+build2-0ubuntu0.16.04.1 | 52.0+build2-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 52.0.2+build1-0ubuntu0.16.04.1 | 52.0.2+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= unspecified < 52 | 52 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xmh3-55xm-hpg9: An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furthe
ghsa_unreviewed·2022-05-14
CVE-2017-5415 [MEDIUM] CWE-20 GHSA-xmh3-55xm-hpg9: An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furthe
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
OSV
firefox regression
osv·2017-03-30·CVSS 9.8
[CRITICAL] firefox regression
firefox regression
USN-3216-1 fixed vulnerabilities in Firefox. The update resulted in a
startup crash when Firefox is used with XRDP. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017-5407, CVE-2017-5408, CVE-2017-5410, CVE-2017-5412,
CVE-2017-541
OSV
firefox vulnerabilities
osv·2017-03-07·CVSS 9.8
CVE-2017-5398 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017-5407, CVE-2017-5408, CVE-2017-5410, CVE-2017-5412,
CVE-2017-5413, CVE-2017-5414, CVE-2017-5415, CVE-2017-5416, CVE-2017-5417,
CVE-2017-5418, CVE-2017-5419, CVE-2017-5420, CVE-2017-5421, CVE-2017-5422,
CVE-2017-5426, CVE-2017-5427)
OSV
CVE-2017-5415: An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furthe
osv·2017-03-07·CVSS 5.3
CVE-2017-5415 [MEDIUM] CVE-2017-5415: An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furthe
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
Ubuntu
Firefox regression
vendor_ubuntu·2017-03-30·CVSS 9.8
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-3216-1 introduced a regression in Firefox.
USN-3216-1 fixed vulnerabilities in Firefox. The update resulted in a
startup crash when Firefox is used with XRDP. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2017-03-07·CVSS 9.8
CVE-2017-5398 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to bypass same origin restrictions, obtain
sensitive information, spoof the addressbar, spoof the print dialog,
cause a denial of service via application crash or hang, or execute
arbitrary code. (CVE-2017-5398, CVE-2017-5399, CVE-2017-5400,
CVE-2017-5401, CVE-2017-5402, CVE-2017-5403, CVE-2017-5404, CVE-2017-5405,
CVE-2017-5406, CVE-2017-5407, CVE-2017-5408, CVE-2017-5410, CVE-2017-5412,
CVE-2017-5413, CVE-2017-5414, CVE-2017-5415, CVE-2017-5416, CVE-2017-5417,
CVE-2017-5418, CVE-2017-5419, CVE
Debian
CVE-2017-5415: firefox - An attack can use a blob URL and script to spoof an arbitrary addressbar URL pre...
vendor_debian·2017·CVSS 5.3
CVE-2017-5415 [MEDIUM] CVE-2017-5415: firefox - An attack can use a blob URL and script to spoof an arbitrary addressbar URL pre...
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
Scope: local
sid: resolved (fixed in 52.0-1)
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96692http://www.securitytracker.com/id/1037966https://bugzilla.mozilla.org/show_bug.cgi?id=1321719https://www.mozilla.org/security/advisories/mfsa2017-05/http://www.securityfocus.com/bid/96692http://www.securitytracker.com/id/1037966https://bugzilla.mozilla.org/show_bug.cgi?id=1321719https://www.mozilla.org/security/advisories/mfsa2017-05/
2018-06-11
Published