cbcvebase.
CVE-2024-0748
published 2024-01-23

CVE-2024-0748: A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 122.0-1 (sid)firefox 122.0-1 (sid)
mozillafirefox< 122.0122.0
mozillafirefox
mozillafirefox>= 0 < 122.0+build2-0ubuntu0.20.04.1122.0+build2-0ubuntu0.20.04.1
mozillafirefox>= 0 < 122.0.1+build1-0ubuntu0.20.04.1122.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 122122

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv6.5MEDIUM