CVE-2024-11701

medium

Description

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.

References

https://www.mozilla.org/security/advisories/mfsa2024-67/

https://www.mozilla.org/security/advisories/mfsa2024-63/

https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-33966

https://bugzilla.mozilla.org/show_bug.cgi?id=1914797

Details

Source: Mitre, NVD

Published: 2024-11-26

Updated: 2025-04-05

Named Vulnerability: GHSA-p9vw-xw86-3f2w

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00393