cbcvebase.
CVE-2017-7763
published 2018-06-11

CVE-2017-7763: Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing…

PriorityP425medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.14%
63.3th percentile
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianfirefox
debianfirefox-esr
mozillafirefox< 52.2.052.2.0
mozillafirefox< 54.054.0
mozillafirefox>= unspecified < 5454
mozillafirefox_esr>= unspecified < 52.252.2
mozillathunderbird< 52.2.052.2.0
mozillathunderbird>= unspecified < 52.252.2

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_debian5.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.