CVE-2024-8383
published 2024-09-03CVE-2024-8383: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did…
high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 130.0-1 (sid) | firefox 130.0-1 (sid) |
| debian | firefox-esr | < firefox 130.0-1 (sid) | firefox 130.0-1 (sid) |
| debian | thunderbird | < firefox 130.0-1 (sid) | firefox 130.0-1 (sid) |
| mozilla | firefox | < 130.0 | 130.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 130.0+build2-0ubuntu0.20.04.1 | 130.0+build2-0ubuntu0.20.04.1 |
| mozilla | firefox | >= 0 < 130.0.1+build1-0ubuntu0.20.04.1 | 130.0.1+build1-0ubuntu0.20.04.1 |
| mozilla | firefox | >= unspecified < 130 | 130 |
| mozilla | firefox_esr | < 115.15 | 115.15 |
| mozilla | firefox_esr | >= 128.0 < 128.2 | 128.2 |
| mozilla | firefox_esr | >= unspecified < 128.2 | 128.2 |
| mozilla | firefox_esr | >= unspecified < 115.15 | 115.15 |
| mozilla | thunderbird | >= 0 < 1:115.15.0-1~deb11u1 | 1:115.15.0-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:115.15.0-1~deb12u1 | 1:115.15.0-1~deb12u1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv9.8CRITICAL
Ubuntu
Firefox regressions
vendor_ubuntu·2024-09-23·CVSS 9.8
[CRITICAL] Firefox regressions
Title: Firefox regressions
Summary: USN-6992-1 caused some minor regressions in Firefox.
USN-6992-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cau
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2024-09-05·CVSS 9.8
CVE-2024-8385 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-8381)
It was discovered that Firefox did not properly manage memory during
garbage collection. An attacker could potentially exploi
Red Hat
mozilla: Firefox did not ask before openings news: links in an external application
vendor_redhat·2024-09-03·CVSS 7.5
CVE-2024-8383 [HIGH] CWE-862 mozilla: Firefox did not ask before openings news: links in an external application
mozilla: Firefox did not ask before openings news: links in an external application
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
The Mozilla Foundation's Security Advisory: Firefox normally asks for confirmation before asking the operating system to find an appl
Debian
CVE-2024-8383: firefox - Firefox normally asks for confirmation before asking the operating system to fin...
vendor_debian·2024·CVSS 7.5
CVE-2024-8383 [HIGH] CVE-2024-8383: firefox - Firefox normally asks for confirmation before asking the operating system to fin...
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Scope: local
sid: resolved (fixed in 130.0-1)
Mozilla
Mozilla Foundation Security Advisory 2024-41: CVE-2024-8383
vendor_mozilla·CVSS 7.5
CVE-2024-8383 [HIGH] Mozilla Foundation Security Advisory 2024-41: CVE-2024-8383
Mozilla Foundation Security Advisory 2024-41
CVE: CVE-2024-8383
Product: Firefox ESR
Impact: moderate
Fixed in: Firefox ESR 115.15
Mozilla
Mozilla Foundation Security Advisory 2024-39: CVE-2024-8383
vendor_mozilla·CVSS 7.5
CVE-2024-8383 [HIGH] Mozilla Foundation Security Advisory 2024-39: CVE-2024-8383
Mozilla Foundation Security Advisory 2024-39
CVE: CVE-2024-8383
Product: Firefox
Impact: high
Fixed in: Firefox 130
Mozilla
Mozilla Foundation Security Advisory 2024-40: CVE-2024-8383
vendor_mozilla·CVSS 7.5
CVE-2024-8383 [HIGH] Mozilla Foundation Security Advisory 2024-40: CVE-2024-8383
Mozilla Foundation Security Advisory 2024-40
CVE: CVE-2024-8383
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 128.2
OSV
firefox regressions
osv·2024-09-23·CVSS 9.8
CVE-2024-8382 [CRITICAL] firefox regressions
firefox regressions
USN-6992-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-8381)
It
OSV
firefox vulnerabilities
osv·2024-09-05·CVSS 9.8
CVE-2024-8382 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-8382,
CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389)
Nils Bars discovered that Firefox contained a type confusion vulnerability
when performing certain property name lookups. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-8381)
It was discovered that Firefox did not properly manage memory during
garbage collection. An attacker could potentially exploit this issue to
cause a denial of service, or execute arbitrary
OSV
CVE-2024-8383: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support
osv·2024-09-03·CVSS 7.5
CVE-2024-8383 [HIGH] CVE-2024-8383: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
GHSA
GHSA-794f-5gfq-xmmq: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support
ghsa_unreviewed·2024-09-03
CVE-2024-8383 [HIGH] CWE-1188 GHSA-794f-5gfq-xmmq: Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1908496https://www.mozilla.org/security/advisories/mfsa2024-39/https://www.mozilla.org/security/advisories/mfsa2024-40/https://www.mozilla.org/security/advisories/mfsa2024-41/https://lists.debian.org/debian-lts-announce/2024/09/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00025.html
2024-09-03
Published