Vulnerability · NVD
CVE-2024-6608
MEDIUM 4.3
Vendor bulletin scale — NVD CVSS pending
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
EPSS
0.38%
exploit very unlikely
percentile 30.5%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| mozilla |
thunderbird All platforms (wildcard)
|
All platforms (wildcard) | <128.0 | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |