Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade firefox-esrUpgrade thunderbirdUpgrade firefoxUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade libxulUpgrade linux-thunderbird | Jan 25, 2017 | Jan 24, 2017 |
| Suse | — | Upgrade mozillafirefoxUpgrade mozillafirefox-develUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-translations-common | Feb 2, 2017 | Jan 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub