VDB

DEBIAN-CVE-2017-5383

DEBIAN-CVE-2017-5383 PUBLISHED CVSS 5.300000190734863 MEDIUM

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Risk Scores

CVSS 3.0
5.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Debian:14firefox-esr0, 0, 0
Debian:12firefox-esr0, 0, 0
Debian:11firefox-esr0, 0, 0
Debian:13firefox-esr0, 0, 0

Timeline

  • Jun 11, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›