The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. This can lead to user confusion. *This vulnerability only affects Firefox for Android < 62.*
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2018-20/ | vendor advisory |
http://www.securitytracker.com/id/1041610 | vdb entry third party advisory |
http://www.securityfocus.com/bid/105276 | vdb entry third party advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1479311 | issue tracking exploit vendor advisory |