cbcvebase.
CVE-2017-5451
published 2018-06-11

CVE-2017-5451: A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text…

PriorityP417medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EPSS
1.51%
71.6th percentile
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianfirefox< firefox 52.0.1-1 (sid)firefox 52.0.1-1 (sid)
mozillafirefox< 53.053.0
mozillafirefox< 52.1.052.1.0
mozillafirefox>= 0 < 53.0+build6-0ubuntu0.14.04.153.0+build6-0ubuntu0.14.04.1
mozillafirefox>= 0 < 53.0.2+build1-0ubuntu0.14.04.253.0.2+build1-0ubuntu0.14.04.2
mozillafirefox>= 0 < 53.0+build6-0ubuntu0.16.04.153.0+build6-0ubuntu0.16.04.1
mozillafirefox>= 0 < 53.0.2+build1-0ubuntu0.16.04.253.0.2+build1-0ubuntu0.16.04.2
mozillafirefox>= unspecified < 5353
mozillafirefox_esr>= unspecified < 52.152.1
mozillathunderbird< 52.1.052.1.0
mozillathunderbird>= 0 < 1:52.1.1+build1-0ubuntu0.14.04.11:52.1.1+build1-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:52.1.1+build1-0ubuntu0.16.04.11:52.1.1+build1-0ubuntu0.16.04.1
mozillathunderbird>= unspecified < 52.152.1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.