Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99764
HistoryDec 10, 2021 - 12:00 a.m.

Mozilla Firefox ESR input validation error vulnerability

2021-12-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.001 Low

EPSS

Percentile

40.2%

Mozilla Firefox, an open source Web browser from the Mozilla Foundation, is vulnerable to an input validation error in Mozilla Firefox ESR that results from a parameter URL containing spaces that is not properly escaped when invoking a protocol handler for an external protocol. A remote attacker could trick a victim into clicking on a specially crafted link and passing the unescaped input to a third-party application via a URI handler.

CPENameOperatorVersion
mozilla firefoxlt95.0