Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability affects Firefox < 57.
http://www.securityfocus.com/bid/101832
http://www.securitytracker.com/id/1039803
Source: MITRE
Published: 2018-06-11
Updated: 2018-06-25
Type: CWE-20
Base Score: 5
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
Impact Score: 2.9
Exploitability Score: 10
Severity: MEDIUM
Base Score: 5.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Impact Score: 1.4
Exploitability Score: 3.9
Severity: MEDIUM
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 56.0.2 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
700322 | Mozilla Firefox < 57 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | critical |
105542 | Ubuntu 14.04 LTS / 16.04 LTS / 17.04 / 17.10 : firefox regression (USN-3477-4) | Nessus | Ubuntu Local Security Checks | critical |
104994 | Ubuntu 14.04 LTS / 16.04 LTS / 17.04 / 17.10 : firefox regressions (USN-3477-3) | Nessus | Ubuntu Local Security Checks | critical |
104807 | Ubuntu 14.04 LTS / 16.04 LTS / 17.04 / 17.10 : firefox regression (USN-3477-2) | Nessus | Ubuntu Local Security Checks | critical |
104652 | Ubuntu 14.04 LTS / 16.04 LTS / 17.04 / 17.10 : firefox vulnerabilities (USN-3477-1) | Nessus | Ubuntu Local Security Checks | critical |
104638 | Mozilla Firefox < 57 Multiple Vulnerabilities | Nessus | Windows | critical |
104637 | Mozilla Firefox ESR < 52.5 Multiple Vulnerabilities | Nessus | Windows | critical |
104636 | Mozilla Firefox < 57 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | critical |
104635 | Mozilla Firefox ESR < 52.5 Multiple Vulnerabilities (macOS) | Nessus | MacOS X Local Security Checks | critical |
104564 | FreeBSD : mozilla -- multiple vulnerabilities (f78eac48-c3d1-4666-8de5-63ceea25a578) | Nessus | FreeBSD Local Security Checks | critical |