cbcvebase.
CVE-2023-6206
published 2023-11-21

CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact…

medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianfirefox< firefox 120.0-1 (sid)firefox 120.0-1 (sid)
debianfirefox-esr< firefox 120.0-1 (sid)firefox 120.0-1 (sid)
debianthunderbird< firefox 120.0-1 (sid)firefox 120.0-1 (sid)
mozillafirefox< 120.0120.0
mozillafirefox
mozillafirefox>= 0 < 120.0+build2-0ubuntu0.20.04.1120.0+build2-0ubuntu0.20.04.1
mozillafirefox>= 0 < 120.0.1+build1-0ubuntu0.20.04.1120.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 120120
mozillafirefox_esr< 115.5.0115.5.0
mozillafirefox_esr>= unspecified < 115.5.0115.5.0
mozillathunderbird< 115.5115.5
mozillathunderbird>= 0 < 1:115.5.0-1~deb11u11:115.5.0-1~deb11u1
mozillathunderbird>= 0 < 1:115.5.0-1~deb12u11:115.5.0-1~deb12u1
mozillathunderbird>= 0 < 1:115.5.0-11:115.5.0-1
mozillathunderbird>= 0 < 1:115.5.0-11:115.5.0-1
mozillathunderbird>= 0 < 1:115.5.0+build1-0ubuntu0.20.04.11:115.5.0+build1-0ubuntu0.20.04.1
mozillathunderbird>= 0 < 1:115.5.0+build1-0ubuntu0.22.04.11:115.5.0+build1-0ubuntu0.22.04.1
mozillathunderbird>= unspecified < 115.5115.5

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
osv6.5MEDIUM