6.5
CVE-2025-23109
- EPSS 1.11%
- Veröffentlicht 11.01.2025 04:15:06
- Zuletzt bearbeitet 13.04.2026 15:16:54
- Quelle security@mozilla.org
- CVE-Watchlists
- Unerledigt
Address bar spoofing on iOS using long hostnames
Long hostnames in URLs could be leveraged to obscure the actual host of the website or spoof the website address. This vulnerability was fixed in Firefox for iOS 134.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.11% | 0.782 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.