Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-8386

Опубликовано: 03 сент. 2024
Источник: debian
EPSS Низкий

Описание

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed130.0-1package
thunderbirdfixed1:128.2.0esr-1package
thunderbirdnot-affectedbookwormpackage
thunderbirdnot-affectedbullseyepackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2024-39/#CVE-2024-8386

  • https://www.mozilla.org/en-US/security/advisories/mfsa2024-43/#CVE-2024-8386

EPSS

Процентиль: 42%
0.00192
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
10 месяцев назад

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

CVSS3: 6.1
redhat
10 месяцев назад

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

CVSS3: 6.1
nvd
10 месяцев назад

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

CVSS3: 6.1
github
10 месяцев назад

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130 and Firefox ESR < 128.2.

CVSS3: 4.3
fstec
10 месяцев назад

Уязвимость браузера Mozilla Firefox, связанная с некорректным ограничением визуализированных слоев пользовательского интерфейса, позволяющая нарушителю проводить спуфинг атаки

EPSS

Процентиль: 42%
0.00192
Низкий