CVE-2024-8383Initialization of a Resource with an Insecure Default in Mozilla Firefox

Severity
7.5HIGHNVD
OSV9.8
EPSS
0.2%
top 55.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 3
Latest updateSep 23

Description

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vul

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages6 packages

CVEListV5mozilla/firefoxunspecified130
NVDmozilla/firefox< 130.0
CVEListV5mozilla/firefox_esrunspecified128.2+1
NVDmozilla/firefox_esr128.0128.2+1
Ubuntumozilla/firefox< 130.0+build2-0ubuntu0.20.04.1

🔴Vulnerability Details

5
OSV
firefox regressions2024-09-23
OSV
firefox vulnerabilities2024-09-05
OSV
CVE-2024-8383: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support2024-09-03
CVEList
CVE-2024-8383: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support2024-09-03
GHSA
GHSA-794f-5gfq-xmmq: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support2024-09-03

📋Vendor Advisories

6
Ubuntu
Firefox vulnerabilities2024-09-05
Red Hat
mozilla: Firefox did not ask before openings news: links in an external application2024-09-03
Debian
CVE-2024-8383: firefox - Firefox normally asks for confirmation before asking the operating system to fin...2024
Mozilla
Mozilla Foundation Security Advisory 2024-41: CVE-2024-8383
Mozilla
Mozilla Foundation Security Advisory 2024-39: CVE-2024-8383
CVE-2024-8383 — Mozilla Firefox vulnerability | cvebase