Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2024-4767
HistoryMay 14, 2024 - 6:15 p.m.

CVE-2024-4767

2024-05-1418:15:13
Debian Security Bug Tracker
security-tracker.debian.org
14
cve-2024-4767
browser preference
indexeddb
deletion vulnerability
firefox
thunderbird
unix

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

10.3%

If the browser.privatebrowsing.autostart preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0

Percentile

10.3%