CVE-2024-11698
published 2024-11-26CVE-2024-11698: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened…
critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted.
*This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| mozilla | firefox | < 128.5.0 | 128.5.0 |
| mozilla | firefox | < 133.0 | 133.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= unspecified < 133 | 133 |
| mozilla | firefox_esr | >= unspecified < 128.5 | 128.5 |
| mozilla | thunderbird | < 128.5.0 | 128.5.0 |
| mozilla | thunderbird | >= 129.0 < 133.0 | 133.0 |
| mozilla | thunderbird | >= unspecified < 133 | 133 |
| mozilla | thunderbird | >= unspecified < 128.5 | 128.5 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
Red Hat
firefox: thunderbird: Fullscreen Lock-Up When Modal Dialog Interrupts Transition on macOS
vendor_redhat·2024-11-26·CVSS 9.8
CVE-2024-11698 [CRITICAL] CWE-755 firefox: thunderbird: Fullscreen Lock-Up When Modal Dialog Interrupts Transition on macOS
firefox: thunderbird: Fullscreen Lock-Up When Modal Dialog Interrupts Transition on macOS
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted.
*This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
A flaw was found in Mozilla. The Mozilla Foundation's Security Advisory describes the following issue: A flaw in han
Debian
CVE-2024-11698: firefox - A flaw in handling fullscreen transitions may have inadvertently caused the appl...
vendor_debian·2024·CVSS 9.8
CVE-2024-11698 [CRITICAL] CVE-2024-11698: firefox - A flaw in handling fullscreen transitions may have inadvertently caused the appl...
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted. *This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-68: CVE-2024-11698
vendor_mozilla·CVSS 9.8
CVE-2024-11698 [CRITICAL] Mozilla Foundation Security Advisory 2024-68: CVE-2024-11698
Mozilla Foundation Security Advisory 2024-68
CVE: CVE-2024-11698
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 128.5
Mozilla
Mozilla Foundation Security Advisory 2024-67: CVE-2024-11698
vendor_mozilla·CVSS 9.8
CVE-2024-11698 [CRITICAL] Mozilla Foundation Security Advisory 2024-67: CVE-2024-11698
Mozilla Foundation Security Advisory 2024-67
CVE: CVE-2024-11698
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 133
Mozilla
Mozilla Foundation Security Advisory 2024-64: CVE-2024-11698
vendor_mozilla·CVSS 9.8
CVE-2024-11698 [CRITICAL] Mozilla Foundation Security Advisory 2024-64: CVE-2024-11698
Mozilla Foundation Security Advisory 2024-64
CVE: CVE-2024-11698
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 128.5
Mozilla
Mozilla Foundation Security Advisory 2024-63: CVE-2024-11698
vendor_mozilla·CVSS 9.8
CVE-2024-11698 [CRITICAL] Mozilla Foundation Security Advisory 2024-63: CVE-2024-11698
Mozilla Foundation Security Advisory 2024-63
CVE: CVE-2024-11698
Product: Firefox
Impact: high
Fixed in: Firefox 133
OSV
CVE-2024-11698: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was ope
osv·2024-11-26·CVSS 9.8
CVE-2024-11698 [CRITICAL] CVE-2024-11698: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was ope
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted. *This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
GHSA
GHSA-m59j-fmqm-3q93: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was ope
ghsa_unreviewed·2024-11-26
CVE-2024-11698 [CRITICAL] GHSA-m59j-fmqm-3q93: A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was ope
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until the browser is restarted.
*This bug only affects the application when running on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-26
Published