Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-38506

Опубликовано: 08 дек. 2021
Источник: debian
EPSS Низкий

Описание

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed94.0-1package
firefox-esrfixed91.3.0esr-1package
thunderbirdfixed1:91.3.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-48/#CVE-2021-38506

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-49/#CVE-2021-38506

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-50/#CVE-2021-38506

EPSS

Процентиль: 50%
0.00269
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 4 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 7.5
redhat
около 4 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
nvd
около 4 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
github
около 4 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 5.4
fstec
около 4 лет назад

Уязвимость браузера Mozilla Firefox, связанная с недостаточным предупреждением об опасных действиях, позволяющая нарушителю провести атаку с использованием спуфинга

EPSS

Процентиль: 50%
0.00269
Низкий