Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2024-4773
HistoryMay 14, 2024 - 6:15 p.m.

CVE-2024-4773

2024-05-1418:15:15
Debian Security Bug Tracker
security-tracker.debian.org
12
network error
page content
url bar
spoofing
firefox
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

25.8%

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.

OSVersionArchitecturePackageVersionFilename
Debian999allfirefox< 126.0-1firefox_126.0-1_all.deb

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

25.8%