CVE-2024-11701
published 2024-11-26CVE-2024-11701: The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible…
medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 133.0-1 (sid) | firefox 133.0-1 (sid) |
| mozilla | firefox | < 133.0 | 133.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 133.0+build2-0ubuntu0.20.04.1 | 133.0+build2-0ubuntu0.20.04.1 |
| mozilla | firefox | >= unspecified < 133 | 133 |
| mozilla | thunderbird | < 133.0 | 133.0 |
| mozilla | thunderbird | >= unspecified < 133 | 133 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv4.3MEDIUM
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2024-12-03·CVSS 4.3
CVE-2024-11692 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-11692,
CVE-2024-11694, CVE-2024-11695, CVE-2024-11696, CVE-2024-11697,
CVE-2024-11699, CVE-2024-11701, CVE-2024-11704, CVE-2024-11705,
CVE-2024-11706, CVE-2024-11708)
Instructions: After a standard system update you need to restart Firefox to make all the
necessary changes
Red Hat
firefox: thunderbird: Misleading Address Bar State During Navigation Interruption
vendor_redhat·2024-11-26·CVSS 4.3
CVE-2024-11701 [MEDIUM] CWE-451 firefox: thunderbird: Misleading Address Bar State During Navigation Interruption
firefox: thunderbird: Misleading Address Bar State During Navigation Interruption
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
A flaw was found in Mozilla. The Mozilla Foundation's Security Advisory describes the following issue: The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks.
Statement: This CVE is not relevant for mail usage, thus the impact has been lowered to Low.
Package: firefox (Red Hat Enterprise Linux 10) - Fix deferred
Package: thunderbird (Red Hat Enterprise
Debian
CVE-2024-11701: firefox - The incorrect domain may have been displayed in the address bar during an interr...
vendor_debian·2024·CVSS 4.3
CVE-2024-11701 [MEDIUM] CVE-2024-11701: firefox - The incorrect domain may have been displayed in the address bar during an interr...
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Scope: local
sid: resolved (fixed in 133.0-1)
Mozilla
Mozilla Foundation Security Advisory 2024-67: CVE-2024-11701
vendor_mozilla·CVSS 4.3
CVE-2024-11701 [MEDIUM] Mozilla Foundation Security Advisory 2024-67: CVE-2024-11701
Mozilla Foundation Security Advisory 2024-67
CVE: CVE-2024-11701
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 133
Mozilla
Mozilla Foundation Security Advisory 2024-63: CVE-2024-11701
vendor_mozilla·CVSS 4.3
CVE-2024-11701 [MEDIUM] Mozilla Foundation Security Advisory 2024-63: CVE-2024-11701
Mozilla Foundation Security Advisory 2024-63
CVE: CVE-2024-11701
Product: Firefox
Impact: high
Fixed in: Firefox 133
OSV
firefox vulnerabilities
osv·2024-12-03·CVSS 4.3
CVE-2024-11692 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-11692,
CVE-2024-11694, CVE-2024-11695, CVE-2024-11696, CVE-2024-11697,
CVE-2024-11699, CVE-2024-11701, CVE-2024-11704, CVE-2024-11705,
CVE-2024-11706, CVE-2024-11708)
OSV
CVE-2024-11701: The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt
osv·2024-11-26·CVSS 4.3
CVE-2024-11701 [MEDIUM] CVE-2024-11701: The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
GHSA
GHSA-p9vw-xw86-3f2w: The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt
ghsa_unreviewed·2024-11-26
CVE-2024-11701 [MEDIUM] CWE-290 GHSA-p9vw-xw86-3f2w: The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-26
Published