CVE-2024-38313
published 2024-06-13CVE-2024-38313: In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This…
PriorityP416medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.24%
15.6th percentile
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 127.0 | 127.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_for_ios | >= unspecified < 127 | 127 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-38313: firefox - In certain scenarios a malicious website could attempt to display a fake locatio...
vendor_debian·2024·CVSS 4.3
CVE-2024-38313 [MEDIUM] CVE-2024-38313: firefox - In certain scenarios a malicious website could attempt to display a fake locatio...
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-27: CVE-2024-38313
vendor_mozilla·CVSS 4.3
CVE-2024-38313 [MEDIUM] Mozilla Foundation Security Advisory 2024-27: CVE-2024-38313
Mozilla Foundation Security Advisory 2024-27
CVE: CVE-2024-38313
Product: Firefox for iOS
Impact: moderate
Fixed in: Firefox for iOS 127
GHSA
GHSA-f78g-xm2r-gm6j: In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address T
ghsa_unreviewed·2024-06-13
CVE-2024-38313 [MEDIUM] CWE-451 GHSA-f78g-xm2r-gm6j: In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address T
In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-13
Published