Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5hw-4fxj-g4x6

Опубликовано: 01 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 131.

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox < 131.

EPSS

Процентиль: 53%
0.00306
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVSS3: 7.1
redhat
около 1 года назад

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVSS3: 6.5
nvd
около 1 года назад

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVSS3: 6.5
debian
около 1 года назад

A user who enables full-screen mode on a specially crafted web page co ...

CVSS3: 5.4
fstec
около 1 года назад

Уязвимость полноэкранного режима (Full Screen Mode) браузера Mozilla Firefox Focus операционных систем Android, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 53%
0.00306
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-290