cbcvebase.
CVE-2024-6608
published 2024-07-09

CVE-2024-6608: It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 128.0-1 (sid)firefox 128.0-1 (sid)
mozillafirefox< 128.0128.0
mozillafirefox
mozillafirefox>= 0 < 128.0+build2-0ubuntu0.20.04.1128.0+build2-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 128128
mozillathunderbird< 128.0128.0
mozillathunderbird>= unspecified < 128128
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv4.7MEDIUM