Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18086
HistoryMay 02, 2019 - 6:12 a.m.

Arbitrary Code Execution

2019-05-0206:12:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.003

Percentile

70.6%

Mozilla Firefox is vulnerable to Arbitrary Code Execution. This is because a flaw exists in the isLabelSafe() function in nsIDNService.cpp that is triggered when handling characters from different unicode blocks. An unauthenticated, remote attacker can exploit this, via a specially crafted IDN domain, to spoof a valid URL and conduct phishing attacks.