Required CVE Record Information
Description
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
References 4 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://www.mozilla.org/security/advisories/mfsa2017-05/ x_transferred
- securitytracker.com: 1037966 vdb-entryx_transferred
- https://bugzilla.mozilla.org/show_bug.cgi?id=1321719 x_transferred
- securityfocus.com: 96692 vdb-entryx_transferred