SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-32205

This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

MEDIUM 4.3EPSS 0.63%

Does this matter?

Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.

Description

In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
0.63% probability · 48th percentile
CISA KEV
Not listed
Affected
mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird
Source
security@mozilla.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.