CVE-2024-31393
published 2024-04-03CVE-2024-31393: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox…
medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 124.0 | 124.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_for_ios | >= unspecified < 124 | 124 |
GHSA
GHSA-x945-jm33-f3qv: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects
ghsa_unreviewed·2024-04-03
CVE-2024-31393 [MEDIUM] GHSA-x945-jm33-f3qv: Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
Debian
CVE-2024-31393: firefox - Dragging Javascript URLs to the address bar could cause them to be loaded, bypas...
vendor_debian·2024·CVSS 4.3
CVE-2024-31393 [MEDIUM] CVE-2024-31393: firefox - Dragging Javascript URLs to the address bar could cause them to be loaded, bypas...
Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-17: CVE-2024-31393
vendor_mozilla·CVSS 4.3
CVE-2024-31393 [MEDIUM] Mozilla Foundation Security Advisory 2024-17: CVE-2024-31393
Mozilla Foundation Security Advisory 2024-17
CVE: CVE-2024-31393
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 124
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-03
Published