cbcvebase.
CVE-2024-8386
published 2024-09-03

CVE-2024-8386: If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 130.0-1 (sid)firefox 130.0-1 (sid)
debianthunderbird< firefox 130.0-1 (sid)firefox 130.0-1 (sid)
mozillafirefox< 130.0130.0
mozillafirefox
mozillafirefox>= 0 < 130.0+build2-0ubuntu0.20.04.1130.0+build2-0ubuntu0.20.04.1
mozillafirefox>= 0 < 130.0.1+build1-0ubuntu0.20.04.1130.0.1+build1-0ubuntu0.20.04.1
mozillafirefox>= unspecified < 130130
mozillafirefox_esr< 128.2128.2
mozillafirefox_esr>= unspecified < 128.2128.2
mozillathunderbird>= 0 < 1:128.2.0esr-11:128.2.0esr-1
mozillathunderbird>= 0 < 1:128.2.0esr-11:128.2.0esr-1
mozillathunderbird>= unspecified < 128.2128.2

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv9.8CRITICAL