Medium severity5.3NVD Advisory· Published Jun 11, 2018· Updated Jun 17, 2026
CVE-2017-7832
CVE-2017-7832
Description
The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweed
< 128.5.1-1.1+ 1 more
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 92.0-1.2
- Range: unspecified
Patches
Vulnerability mechanics
References
4- www.securityfocus.com/bid/101832nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1039803nvdThird Party AdvisoryVDB Entry
- www.mozilla.org/security/advisories/mfsa2017-24/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.