CVE-2017-5394: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
Affected products
- Mozilla Firefox: before 51.0 (fixed in 51.0)
Published 2018-06-11. Last modified 2026-06-17.