Related Vulnerabilities: CVE-2017-5417  

When dragging content from the primary browser pane to the address bar on a malicious site, it is possible to change the address bar so that the displayed location following navigation does not match the URL of the newly loaded page. This allows for spoofing attacks.

Severity Medium

Remote Yes

Type Content spoofing

Description

When dragging content from the primary browser pane to the address bar on a malicious site, it is possible to change the address bar so that the displayed location following navigation does not match the URL of the newly loaded page. This allows for spoofing attacks.

AVG-194 firefox 51.0.1-1 52.0-1 Critical Fixed

10 Mar 2017 ASA-201703-3 AVG-194 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/#CVE-2017-5417
https://bugzilla.mozilla.org/show_bug.cgi?id=791597