peter bassill · operator
$ cve CVE-2017-7783 JSON

CVE-2017-7783 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 14.1% (pctl 96)

Patch early

A public exploit exists.

Description

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS14.12% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2018-06-11
Last modified2026-06-17

Affected (1)

VendorProduct
mozillafirefox

Public exploits

SourceTitleDate
exploit-dbMozilla Firefox < 55 - Denial of Service2017-10-20

References

→ the Explorer  ·  watch your stack  ·  NVD