4.3
CVE-2023-5721
- EPSS 0.78%
- Veröffentlicht 25.10.2023 18:17:43
- Zuletzt bearbeitet 21.11.2024 08:42:21
- Erkennungen
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox ESR Version < 115.4
Mozilla ≫ Thunderbird Version < 115.4.1
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.511 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://bugzilla.mozilla.org/show_bug.cgi?id=1830820
https://lists.debian.org/debian-lts-announce/2023/10/msg00037.html
https://lists.debian.org/debian-lts-announce/2023/10/msg00042.html
https://www.debian.org/security/2023/dsa-5535
https://www.debian.org/security/2023/dsa-5538
https://www.mozilla.org/security/advisories/mfsa2023-45/
https://www.mozilla.org/security/advisories/mfsa2023-46/
https://www.mozilla.org/security/advisories/mfsa2023-47/