Lucene search

K
freebsdFreeBSDAA1C7AF9-570E-11EF-A43E-B42E991FC52E
HistoryJun 11, 2024 - 12:00 a.m.

mozilla firefox -- protocol information guessing

2024-06-1100:00:00
vuxml.freebsd.org
5
mozilla
firefox
protocol handlers
vulnerability
thunderbird
unix

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

6.3

Confidence

Low

[email protected] reports:

By monitoring the time certain operations take, an attacker could
have guessed which external protocol handlers were functional on a
user’s system. This vulnerability affects Firefox < 127,
Firefox ESR < 115.12, and Thunderbird < 115.12.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchfirefox< 127.0,2UNKNOWN

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

6.3

Confidence

Low