cbcvebase.
CVE-2024-5698
published 2024-06-11

CVE-2024-5698: By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 127.0-1 (sid)firefox 127.0-1 (sid)
mozillafirefox< 127127
mozillafirefox
mozillafirefox>= 0 < 127.0.2+build1-0ubuntu0.20.04.1127.0.2+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 127127

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv8.1HIGH