CVE-2017-7838
Dashboard / Vulnerabilities / CVE-2017-7838
CVE-2017-7838
Published: 11 Jun 2018Last Modified: 10 Mar 2026
Summary:
Details: Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability affects Firefox < 57.
References: , http://www.securityfocus.com/bid/101832, http://www.securitytracker.com/id/1039803, https://www.mozilla.org/security/advisories/mfsa2017-24/, https://bugzilla.mozilla.org/show_bug.cgi?id=1399540
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
