vendor:
Firefox
by:
Amit Sangra
7,5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Firefox
Affected Version From: < Mozilla Firefox 55
Affected Version To: < Mozilla Firefox 55
Patch Exists: YES
Related CWE: CVE-2017-7783
CPE: a:mozilla:firefox:55.0
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2017-7783/, https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3391-3/, https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3391-2/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2017-7783/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2017-7783/, https://www.rapid7.com/db/vulnerabilities/mfsa2017-18-cve-2017-7783/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2017-7783/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows/Linux
2017
Mozilla Firefox < 55 - Forcibly make someone view a web content
If a long user name is used in a username/password combination in a site URL (such as http://UserName:Password@example.com), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service.
Mitigation:
Update to version 55