CVE-2017-7839 PUBLISHED

Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This could be used in social engineering and self-cross-site-scripting (self-XSS) attacks where users are convinced to copy and paste text into the addressbar. This vulnerability affects Firefox < 57.

EPSS 0.63% · 70.2th percentile

Risk Scores

EPSS Score
0.63%
70.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSfirefox0, 56.0+build6-0ubuntu1
Ubuntu:16.04:LTSfirefox42.0+build2-0ubuntu1, 44.0+build3-0ubuntu2, 44.0.1+build1-0ubuntu1
Ubuntu:14.04:LTSfirefox43.0.4+build3-0ubuntu0.14.04.1, 44.0+build3-0ubuntu0.14.04.1, 44.0.1+build2-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →