A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-firefox-esralpine-linux-upgrade-firefoxalpine-linux-upgrade-thunderbirdalpine-linux-upgrade-librewolf | Aug 22, 2024 | Dec 22, 2022 | |
| Mfsa2022 01 | mozilla-firefox-upgrade-96_0 | Jan 12, 2022 | Jan 11, 2022 | |
| Mfsa2022 02 | mozilla-firefox-esr-upgrade-91_5 | Jan 12, 2022 | Jan 11, 2022 | |
| Mozilla Thunderbird | mozilla-thunderbird-upgrade-91_5 | Jan 12, 2022 | Jan 11, 2022 | |
| Suse | — | suse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Feb 12, 2022 | Jan 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub