7.5
CVSSv3

CVE-2017-7783

Published: 11/06/2018 Updated: 30/07/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

If a long user name is used in a username/password combination in a site URL (such as " UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

USN-3391-1 introduced a regression in Firefox ...
This update provides compatible packages for Firefox 55 ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2017-18 Security vulnerabilities fixed in Firefox 55 Announced August 8, 2017 Impact critical Products Firefox Fixed in Firefox 55 ...
A denial of service has been found in Firefox &lt; 550 If a long user name is used in a username/password combination in a site URL (such as UserName:Password@examplecom), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service ...

Exploits

# Exploit Title: Mozilla Firefox &lt; 55 - Forcibly make someone view a web content # Category: Denial of Service # Date: 5/11/17 # CVE : CVE-2017-7783 # Affected Version: &lt; Mozilla Firefox 55 # Tested on: Windows/Linux # Software Link: wwwmozillaorg/en-US/firefox/520/releasenotes/ # Exploit Author: Amit Sangra # Website: Cyber ...
Mozilla Firefox versions prior to 55 suffer from a long username denial of service vulnerability ...