CVE-2017-5463Improper Input Validation in Mozilla Firefox

Severity
5.3MEDIUMNVD
EPSS
0.8%
top 26.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of the addressbar as displayed to users. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5mozilla/firefoxunspecified53
NVDmozilla/firefox< 53.0

Patches

🔴Vulnerability Details

1
GHSA
GHSA-vg32-fmv3-phhm: Android intents can be used to launch Firefox for Android in reader mode with a user specified URL2022-05-14

📋Vendor Advisories

1
Debian
CVE-2017-5463: firefox - Android intents can be used to launch Firefox for Android in reader mode with a ...2017

💬Community

1
Bugzilla
Address bar spoof in reader mode2017-04-20