CVE-2024-31393
published 2024-04-03CVE-2024-31393: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox…
PriorityP418medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.33%
25.4th percentile
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 124.0 | 124.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_for_ios | >= unspecified < 124 | 124 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x945-jm33-f3qv: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects
ghsa_unreviewed·2024-04-03
CVE-2024-31393 [MEDIUM] GHSA-x945-jm33-f3qv: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
Debian
CVE-2024-31393: firefox - Dragging Javascript URLs to the address bar could cause them to be loaded, bypas...
vendor_debian·2024·CVSS 4.3
CVE-2024-31393 [MEDIUM] CVE-2024-31393: firefox - Dragging Javascript URLs to the address bar could cause them to be loaded, bypas...
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-17: CVE-2024-31393
vendor_mozilla·CVSS 4.3
CVE-2024-31393 [MEDIUM] Mozilla Foundation Security Advisory 2024-17: CVE-2024-31393
Mozilla Foundation Security Advisory 2024-17
CVE: CVE-2024-31393
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 124
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-03
Published