Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 137
A spoofing vulnerability has been identified in Mozilla Firefox and Thunderbird. A crafted URL containing specific Unicode characters could have obscured the true origin of the page, potentially leading to a spoofing attack. This issue affects Firefox versions prior to 137, Firefox ESR versions prior to 128.9, Thunderbird versions prior to 137, and Thunderbird ESR versions prior to 128.9.
Exploitation of this vulnerability could lead to a spoofing attack, where the true origin of a webpage is obscured, potentially misleading users.
Users can upgrade to Firefox 137, Firefox ESR 128.9, Thunderbird 137, or Thunderbird ESR 128.9 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.