CVE-2024-0605
published 2024-01-22CVE-2024-0605: Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security…
PriorityP343high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.39%
30.8th percentile
Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox_focus | < 122.0 | 122.0 |
| mozilla | focus_for_ios | >= unspecified < 122 | 122 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wph3-4v72-8x34: Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar
ghsa_unreviewed·2024-01-22
CVE-2024-0605 [HIGH] CWE-362 GHSA-wph3-4v72-8x34: Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar
Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.
Mozilla
Mozilla Foundation Security Advisory 2024-03: CVE-2024-0605
vendor_mozilla·CVSS 7.5
CVE-2024-0605 [HIGH] Mozilla Foundation Security Advisory 2024-03: CVE-2024-0605
Mozilla Foundation Security Advisory 2024-03
CVE: CVE-2024-0605
Product: Focus for iOS
Impact: high
Fixed in: Focus for iOS 122
Suricata
GPL NETBIOS DCERPC Remote Activation bind attempt
suricata·2010-09-23
CVE-2003-0528 GPL NETBIOS DCERPC Remote Activation bind attempt
GPL NETBIOS DCERPC Remote Activation bind attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 135 (msg:"GPL NETBIOS DCERPC Remote Activation bind attempt"; flow:established,to_server; content:"|05|"; content:"|0B|"; within:1; distance:1; byte_test:1,&,1,0,relative; content:"|B8|J|9F|M|1C|}|CF 11 86 1E 00| |AF|n|7C|W"; within:16; distance:29; tag:session,5,packets; reference:bugtraq,8234; reference:bugtraq,8458; reference:cve,2003-0528; reference:cve,2003-0605; reference:cve,2003-0715; reference:nessus,11798; reference:nessus,11835; reference:url,www.microsoft.com/technet/security/bulletin/MS03-039.mspx; classtype:attempted-admin; sid:2102251; rev:17; metadata:created_at 2010_09_23, cve CVE_2003_0528, signature_severity Informational, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
2024-01-22
Published