Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-2609

Опубликовано: 19 мар. 2024
Источник: debian
EPSS Низкий

Описание

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed124.0-1package
firefox-esrfixed115.10.0esr-1package
thunderbirdfixed1:115.10.1-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2024-12/#CVE-2024-2609

  • https://www.mozilla.org/en-US/security/advisories/mfsa2024-19/#CVE-2024-2609

  • https://www.mozilla.org/en-US/security/advisories/mfsa2024-20/#CVE-2024-2609

EPSS

Процентиль: 73%
0.00822
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS3: 6.1
redhat
около 1 года назад

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS3: 6.1
nvd
больше 1 года назад

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS3: 6.1
github
больше 1 года назад

The permission prompt input delay could have expired while the window is not in focus, which made the prompt vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124.

CVSS3: 5.9
fstec
больше 1 года назад

Уязвимость браузера Mozilla Firefox, связанная с ошибками представления информации пользовательским интерфейсом, позволяющая нарушителю провести атаку типа clickjacking («захват клика»)

EPSS

Процентиль: 73%
0.00822
Низкий