Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-38506

Опубликовано: 08 дек. 2021
Источник: debian
EPSS Низкий

Описание

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed94.0-1package
firefox-esrfixed91.3.0esr-1package
thunderbirdfixed1:91.3.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-48/#CVE-2021-38506

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/#CVE-2021-38506

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-50/#CVE-2021-38506

EPSS

Процентиль: 43%
0.00207
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 7.5
redhat
почти 4 года назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
nvd
больше 3 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
github
больше 3 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 5.4
fstec
почти 4 года назад

Уязвимость браузера Mozilla Firefox, связанная с недостаточным предупреждением об опасных действиях, позволяющая нарушителю провести атаку с использованием спуфинга

EPSS

Процентиль: 43%
0.00207
Низкий