CVE-2017-5394: CSRF
Published Jan 24, 2017
·Updated
A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<51
51
Mozilla Firefox<51.0
Google Android
Remediation
Patch Available
Event History
Jan 24, 2017
CVE Published
12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5375
- CVE-2017-5376
- CVE-2017-5377
- CVE-2017-5378
- CVE-2017-5379
- CVE-2017-5380
- CVE-2017-5390
- CVE-2017-5389
- CVE-2017-5396
- CVE-2017-5381
- CVE-2017-5382
- CVE-2017-5383
- CVE-2017-5384
- CVE-2017-5385
- CVE-2017-5386
- CVE-2017-5394
- CVE-2017-5391
- CVE-2017-5392
- CVE-2017-5393
- CVE-2017-5395
- CVE-2017-5387
- CVE-2017-5388
- CVE-2017-5374
- CVE-2017-5373
Frequently Asked Questions
1
What type of attack does CVE-2017-5394 involve?
CVE-2017-5394 involves a location bar spoofing attack.