VulnerabilityModified
CVE-2024-0742
This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
MEDIUM 4.3EPSS 0.60%
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox · mozilla/firefox esr · mozilla/thunderbird · debian/debian linux
- Source
- security@mozilla.org
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1867152Issue Tracking, Permissions Required
- https://lists.debian.org/debian-lts-announce/2024/01/msg00015.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00022.htmlMailing List, Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-01/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-02/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-04/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1867152Issue Tracking, Permissions Required
- https://lists.debian.org/debian-lts-announce/2024/01/msg00015.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00022.htmlMailing List, Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-01/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-02/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-04/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.