#VU9325 Spoofing attack in Mozilla Firefox - CVE-2017-7838
Published: November 15, 2017
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to spoof domain names.
Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion.