A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade thunderbirdUpgrade librewolfUpgrade firefox-esr | Aug 22, 2024 | Dec 22, 2022 |
| Mfsa2022 01 | — | Upgrade to Mozilla Firefox version 96.0Upgrade to the latest version of Mozilla Firefox | Jan 12, 2022 | Jan 11, 2022 |
| Mfsa2022 02 | — | Upgrade to Mozilla Firefox ESR version 91.5Upgrade to the latest version of Mozilla Firefox | Jan 12, 2022 | Jan 11, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.5Upgrade to the latest version of Mozilla Thunderbird | Jan 12, 2022 | Jan 11, 2022 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbirdUpgrade MozillaFirefox-develUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbird-translations-common | Feb 12, 2022 | Jan 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub