Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-23984

Опубликовано: 31 мар. 2021
Источник: debian
EPSS Низкий

Описание

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed87.0-1package
firefox-esrfixed78.9.0esr-1package
thunderbirdfixed1:78.9.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-10/#CVE-2021-23984

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-11/#CVE-2021-23984

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-12/#CVE-2021-23984

EPSS

Процентиль: 50%
0.00267
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 5 лет назад

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 6.1
redhat
почти 5 лет назад

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 6.5
nvd
почти 5 лет назад

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

github
больше 3 лет назад

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Thunderbird < 78.9, and Firefox < 87.

CVSS3: 6.5
fstec
почти 5 лет назад

Уязвимость браузеров Mozilla Firefox, Mozilla Firefox ESR и почтового клиента Thunderbird, связанная с неверным ограничением визуализируемых слоев или фреймов пользовательского интерфейса, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 50%
0.00267
Низкий