CVE-2017-7815 describes a spoofing vulnerability in Mozilla Firefox versions prior to 56, specifically impacting installations with e10 multiprocess disabled. An attacker could leverage the "data:" protocol within an iframe to create a JavaScript-generated modal dialog, displaying an arbitrary domain as its origin to the user. This vulnerability has a CVSS v3 score of 5.3 (Medium), indicating a network-based attack with low impact on integrity and no impact on confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 55.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 56CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.