CVE-2024-43111
published 2024-08-06CVE-2024-43111: Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 129 | 129 |
| mozilla | firefox | — | — |
| mozilla | firefox_for_ios | >= unspecified < 129 | 129 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
OSV
CVE-2024-43111: Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for
osv·2024-08-06·CVSS 6.1
CVE-2024-43111 [MEDIUM] CVE-2024-43111: Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
GHSA
GHSA-cr8r-7g9p-hcx6: Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for
ghsa_unreviewed·2024-08-06
CVE-2024-43111 [CRITICAL] CWE-79 GHSA-cr8r-7g9p-hcx6: Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
Debian
CVE-2024-43111: firefox - Long pressing on a download link could potentially allow Javascript commands to ...
vendor_debian·2024·CVSS 6.1
CVE-2024-43111 [MEDIUM] CVE-2024-43111: firefox - Long pressing on a download link could potentially allow Javascript commands to ...
Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2024-36: CVE-2024-43111
vendor_mozilla·CVSS 6.1
CVE-2024-43111 [MEDIUM] Mozilla Foundation Security Advisory 2024-36: CVE-2024-43111
Mozilla Foundation Security Advisory 2024-36
CVE: CVE-2024-43111
Product: Firefox for iOS
Impact: low
Fixed in: Firefox for iOS 129
No detection rules found.
No public exploits indexed.
2024-08-06
Published