CVE-2017-5394 describes a location bar spoofing vulnerability specifically affecting Firefox for Android versions prior to 51. An attacker could exploit this flaw by combining specific JavaScript events with fullscreen mode to display a malicious page's URL over the content of a legitimate tab. Rated with a CVSS score of 8.8 (High), this vulnerability has a low attack complexity and could lead to high impacts on confidentiality, integrity, and availability if a user is tricked into interacting with the spoofed content. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 51.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 51CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.