CVE-2017-5383 PUBLISHED

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

EPSS 2.44% · 85.1th percentile

Risk Scores

EPSS Score
2.44%
85.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSthunderbird0, 1:45.5.1+build1-0ubuntu0.16.04.1, 1:45.4.0+build1-0ubuntu0.16.04.1
Ubuntu:14.04:LTSfirefox37.0.1+build1-0ubuntu0.14.04.1, 37.0.2+build1-0ubuntu0.14.04.1, 38.0+build3-0ubuntu0.14.04.1
Ubuntu:14.04:LTSthunderbird1:31.7.0+build1-0ubuntu0.14.04.1, 0, 1:24.0+build1-0ubuntu1
Ubuntu:16.04:LTSfirefox46.0.1+build1-0ubuntu0.16.04.2, 47.0+build3-0ubuntu0.16.04.1, 48.0+build2-0ubuntu0.16.04.1

Timeline

References

Open in Interactive Console →