VulnerabilityModified
CVE-2023-5721
This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
MEDIUM 4.3EPSS 0.79%
Does this matter?
Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.
Description
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.79% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1021
- Affected
- mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird · debian/debian linux
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1830820Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00037.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00042.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5535Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5538Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-45/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-46/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-47/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1830820Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00037.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00042.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5535Mailing List, Third Party Advisory
- https://www.debian.org/security/2023/dsa-5538Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-45/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-46/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2023-47/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.