CVE-2017-7807
published 2018-06-11CVE-2017-7807: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by…
PriorityP336high8.1CVSS 3.0
AVNACLPRNUIRSUCHIHAN
EPSS
2.14%
80.0th percentile
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 55.0-1 (sid) | firefox 55.0-1 (sid) |
| debian | firefox-esr | < firefox 55.0-1 (sid) | firefox 55.0-1 (sid) |
| mozilla | firefox | < 55.0 | 55.0 |
| mozilla | firefox | < 52.3.0 | 52.3.0 |
| mozilla | firefox | >= 0 < 55.0.1+build2-0ubuntu0.14.04.2 | 55.0.1+build2-0ubuntu0.14.04.2 |
| mozilla | firefox | >= 0 < 55.0.2+build1-0ubuntu0.14.04.1 | 55.0.2+build1-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 55.0.1+build2-0ubuntu0.16.04.2 | 55.0.1+build2-0ubuntu0.16.04.2 |
| mozilla | firefox | >= 0 < 55.0.2+build1-0ubuntu0.16.04.1 | 55.0.2+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= unspecified < 55 | 55 |
| mozilla | firefox_esr | >= unspecified < 52.3 | 52.3 |
| mozilla | thunderbird | < 52.3.0 | 52.3.0 |
| mozilla | thunderbird | >= 0 < 1:52.3.0+build1-0ubuntu0.14.04.1 | 1:52.3.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:52.3.0+build1-0ubuntu0.16.04.1 | 1:52.3.0+build1-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= unspecified < 52.3 | 52.3 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2017-09-14·CVSS 9.1
CVE-2017-7753 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to bypass same-origin
restrictions, bypass CSP restrictions, obtain sensitive information, spoof
the origin of modal alerts, cause a denial of service via application
crash, or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779,
CVE-2017-7784, CVE-2017-7785, CVE-2017-7787, CVE-2017-7791, CVE-2017-7792,
CVE-2017-7800, CVE-2017-7801, CVE-2017-7802, CVE-2017-7803, CVE-2017-7807,
CVE-2017-7809)
A buffer overflow was discovered when displaying SVG content in some
circumstances. If a user were tricked in to ope
Ubuntu
Firefox regression
vendor_ubuntu·2017-08-17·CVSS 9.1
[CRITICAL] Firefox regression
Title: Firefox regression
Summary: USN-3391-1 introduced a regression in Firefox.
USN-3391-1 fixed vulnerabilities in Firefox. The update introduced a
performance regression with WebExtensions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
bypass sandbox restrictions, obtain sensitive information, spoof the
origin of modal alerts, bypass same origin restrictions, read
uninitialized memory, cause a denial of service via program crash or hang,
or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779, CVE-2017-7780,
CVE-2017-7781, CVE
Ubuntu
Ubufox update
vendor_ubuntu·2017-08-16·CVSS 9.1
[CRITICAL] Ubufox update
Title: Ubufox update
Summary: This update provides compatible packages for Firefox 55.
USN-3391-1 fixed vulnerabilities in Firefox. This update provides the
corresponding update for Ubufox.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
bypass sandbox restrictions, obtain sensitive information, spoof the
origin of modal alerts, bypass same origin restrictions, read
uninitialized memory, cause a denial of service via program crash or hang,
or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779, CVE-2017-7780,
CVE-2017-7781, CVE-2017-7783, CVE-2017-7784, CVE-2017-7785, CVE-2017-7786,
CVE-2017-7787,
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2017-08-15·CVSS 9.1
CVE-2017-7753 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
bypass sandbox restrictions, obtain sensitive information, spoof the
origin of modal alerts, bypass same origin restrictions, read
uninitialized memory, cause a denial of service via program crash or hang,
or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779, CVE-2017-7780,
CVE-2017-7781, CVE-2017-7783, CVE-2017-7784, CVE-2017-7785, CVE-2017-7786,
CVE-2017-7787, CVE-2017-7788, CVE-2017-7789, CVE-2017-7791, CVE-2017-7792,
CVE-2017-7794, CVE-2017-
Red Hat
Mozilla: Domain hijacking through appcache fallback (MFSA 2017-19)
vendor_redhat·2017-08-08·CVSS 8.1
CVE-2017-7807 [HIGH] CWE-829 Mozilla: Domain hijacking through appcache fallback (MFSA 2017-19)
Mozilla: Domain hijacking through appcache fallback (MFSA 2017-19)
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Debian
CVE-2017-7807: firefox - A mechanism that uses AppCache to hijack a URL in a domain using fallback by ser...
vendor_debian·2017·CVSS 8.1
CVE-2017-7807 [HIGH] CVE-2017-7807: firefox - A mechanism that uses AppCache to hijack a URL in a domain using fallback by ser...
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
GHSA
GHSA-4g4m-5m32-4h55: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain
ghsa_unreviewed·2022-05-13
CVE-2017-7807 [HIGH] CWE-20 GHSA-4g4m-5m32-4h55: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
OSV
CVE-2017-7807: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain
osv·2018-06-11·CVSS 8.1
CVE-2017-7807 [HIGH] CVE-2017-7807: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
OSV
thunderbird vulnerabilities
osv·2017-09-14·CVSS 9.1
CVE-2017-7753 [CRITICAL] thunderbird vulnerabilities
thunderbird vulnerabilities
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to bypass same-origin
restrictions, bypass CSP restrictions, obtain sensitive information, spoof
the origin of modal alerts, cause a denial of service via application
crash, or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779,
CVE-2017-7784, CVE-2017-7785, CVE-2017-7787, CVE-2017-7791, CVE-2017-7792,
CVE-2017-7800, CVE-2017-7801, CVE-2017-7802, CVE-2017-7803, CVE-2017-7807,
CVE-2017-7809)
A buffer overflow was discovered when displaying SVG content in some
circumstances. If a user were tricked in to opening a specially crafted
message, an attacker could potentially expl
OSV
firefox regression
osv·2017-08-17·CVSS 9.1
[CRITICAL] firefox regression
firefox regression
USN-3391-1 fixed vulnerabilities in Firefox. The update introduced a
performance regression with WebExtensions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
bypass sandbox restrictions, obtain sensitive information, spoof the
origin of modal alerts, bypass same origin restrictions, read
uninitialized memory, cause a denial of service via program crash or hang,
or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779, CVE-2017-7780,
CVE-2017-7781, CVE-2017-7783, CVE-2017-7784, CVE-2017-7785, CVE-2017-7786,
CVE-201
OSV
ubufox update
osv·2017-08-16·CVSS 9.1
[CRITICAL] ubufox update
ubufox update
USN-3391-1 fixed vulnerabilities in Firefox. This update provides the
corresponding update for Ubufox.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
bypass sandbox restrictions, obtain sensitive information, spoof the
origin of modal alerts, bypass same origin restrictions, read
uninitialized memory, cause a denial of service via program crash or hang,
or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779, CVE-2017-7780,
CVE-2017-7781, CVE-2017-7783, CVE-2017-7784, CVE-2017-7785, CVE-2017-7786,
CVE-2017-7787, CVE-2017-7788, CVE-2017-7789, CVE-2017-7791, CVE-2017-7792,
CVE-2017-7794,
OSV
firefox vulnerabilities
osv·2017-08-15·CVSS 9.1
CVE-2017-7753 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to conduct cross-site scripting (XSS) attacks,
bypass sandbox restrictions, obtain sensitive information, spoof the
origin of modal alerts, bypass same origin restrictions, read
uninitialized memory, cause a denial of service via program crash or hang,
or execute arbitrary code. (CVE-2017-7753, CVE-2017-7779, CVE-2017-7780,
CVE-2017-7781, CVE-2017-7783, CVE-2017-7784, CVE-2017-7785, CVE-2017-7786,
CVE-2017-7787, CVE-2017-7788, CVE-2017-7789, CVE-2017-7791, CVE-2017-7792,
CVE-2017-7794, CVE-2017-7797, CVE-2017-7798, CVE-2017-7799, CVE-2017-7800,
CVE-2017-7801, CVE-2017-7802, CVE-2017-7803, CVE-2017-7806, C
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/100242http://www.securitytracker.com/id/1039124https://access.redhat.com/errata/RHSA-2017:2456https://access.redhat.com/errata/RHSA-2017:2534https://bugzilla.mozilla.org/show_bug.cgi?id=1376459https://security.gentoo.org/glsa/201803-14https://www.debian.org/security/2017/dsa-3928https://www.debian.org/security/2017/dsa-3968https://www.mozilla.org/security/advisories/mfsa2017-18/https://www.mozilla.org/security/advisories/mfsa2017-19/https://www.mozilla.org/security/advisories/mfsa2017-20/http://www.securityfocus.com/bid/100242http://www.securitytracker.com/id/1039124https://access.redhat.com/errata/RHSA-2017:2456https://access.redhat.com/errata/RHSA-2017:2534https://bugzilla.mozilla.org/show_bug.cgi?id=1376459https://security.gentoo.org/glsa/201803-14https://www.debian.org/security/2017/dsa-3928https://www.debian.org/security/2017/dsa-3968https://www.mozilla.org/security/advisories/mfsa2017-18/https://www.mozilla.org/security/advisories/mfsa2017-19/https://www.mozilla.org/security/advisories/mfsa2017-20/
2018-06-11
Published