CVE-2024-0742
Last modified
CVE-2024-0742 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 122.0 |
| Mozilla | Firefox Esr | < 115.7 |
| Mozilla | Thunderbird | < 115.7 |
| Debian | Debian Linux | 10.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1867152Issue Tracking, Permissions Required
- https://lists.debian.org/debian-lts-announce/2024/01/msg00015.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00022.htmlMailing List, Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-01/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-02/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-04/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1867152Issue Tracking, Permissions Required
- https://lists.debian.org/debian-lts-announce/2024/01/msg00015.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00022.htmlMailing List, Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-01/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-02/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2024-04/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-0742?
How severe is CVE-2024-0742?
How do I fix CVE-2024-0742?
Are you affected by CVE-2024-0742?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
