When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade mail/thunderbird to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade web/browser/firefox to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 68.8.0-11.4.22.0.1.69.2 on Solaris 11.4 | Jan 19, 2021 | Apr 24, 2020 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade mozillafirefox-buildsymbolsUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-other | Apr 10, 2020 | Apr 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub