Vulnerability · NVD
CVE-2024-0742
MEDIUM 4.3
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
0.60%
exploit very unlikely
percentile 45.3%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
NVD references 4 distinct products for this CVE — only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | <115.7 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |