CVE-2017-5452: Input Validation
Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2017-5433
- CVE-2017-5435
- CVE-2017-5436
- CVE-2017-5461
- CVE-2017-5459
- CVE-2017-5466
- CVE-2017-5434
- CVE-2017-5432
- CVE-2017-5460
- CVE-2017-5438
- CVE-2017-5439
- CVE-2017-5440
- CVE-2017-5441
- CVE-2017-5442
- CVE-2017-5464
- CVE-2017-5443
- CVE-2017-5444
- CVE-2017-5446
- CVE-2017-5447
- CVE-2017-5465
- CVE-2017-5448
- CVE-2016-10196
- CVE-2017-5454
- CVE-2017-5455
- CVE-2017-5456
- CVE-2017-5469
- CVE-2017-5445
- CVE-2017-5449
- CVE-2017-5450
- CVE-2017-5451
- CVE-2017-5462
- CVE-2017-5463
- CVE-2017-5467
- CVE-2017-5452
- CVE-2017-5453
- CVE-2017-5458
- CVE-2017-5468
- CVE-2017-5430
- CVE-2017-5429
Frequently Asked Questions
What is the severity of CVE-2017-5452?
CVE-2017-5452 has a severity rating of medium, as it allows malicious sites to spoof the address bar on Firefox for Android.
How can I mitigate CVE-2017-5452?
To address CVE-2017-5452, users should update Firefox for Android to version 54 or later, as the vulnerability is fixed in this release.
Who is affected by CVE-2017-5452?
CVE-2017-5452 specifically affects users of Firefox for Android versions below 54.
What kind of attack does CVE-2017-5452 enable?
CVE-2017-5452 enables attackers to display a spoofed address bar, potentially misleading users about the true identity of a website.
Is CVE-2017-5452 affecting other operating systems?
No, CVE-2017-5452 only impacts Firefox for Android and does not affect other operating systems.