PT-2023-3731 · Mozilla+10 · Firefox+12

Shaheen Fazim

·

Published

2023-07-04

·

Updated

2024-12-12

·

CVE-2023-37207

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 115 Firefox ESR versions prior to 102.13 Thunderbird versions prior to 102.13
Description A website could obscure the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could lead to user confusion and possible spoofing attacks. The issue is related to insufficient warning about potentially dangerous actions, which could allow a remote attacker to perform a spoofing attack.
Recommendations For Firefox versions prior to 115, update to version 115 or later to resolve the issue. For Firefox ESR versions prior to 102.13, update to version 102.13 or later to resolve the issue. For Thunderbird versions prior to 102.13, update to version 102.13 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:4063
ALSA-2023:4064
ALSA-2023:4071
ALSA-2023:4076
ALT-PU-2023-4102
ALT-PU-2023-5754
ALT-PU-2023-5836
ALT-PU-2023-6436
ALT-PU-2024-14035
ALT-PU-2024-3614
ALT-PU-2024-3860
ALT-PU-2024-4241
ALT-PU-2024-4748
BDU:2023-04019
CESA-2023_4063
CESA-2023_4076
CVE-2023-37207
DLA-3484-1
DLA-3490-1
DSA-5450-1
DSA-5451-1
MGASA-2023-0235
OESA-2023-1671
OESA-2023-1673
OESA-2023-1674
OPENSUSE-SU-2023_2886-1
OPENSUSE-SU-2024:13037-1
OPENSUSE-SU-2024:13040-1
OPENSUSE-SU-2024:13133-1
OPENSUSE-SU-2024:14572-1
RHSA-2023:4062
RHSA-2023:4063
RHSA-2023:4064
RHSA-2023:4065
RHSA-2023:4066
RHSA-2023:4067
RHSA-2023:4068
RHSA-2023:4069
RHSA-2023:4070
RHSA-2023:4071
RHSA-2023:4072
RHSA-2023:4073
RHSA-2023:4074
RHSA-2023:4075
RHSA-2023:4076
RHSA-2023:4079
RHSA-2023_4062
RHSA-2023_4063
RHSA-2023_4064
RHSA-2023_4071
RHSA-2023_4076
RHSA-2023_4079
RLSA-2023:4063
RLSA-2023:4071
RLSA-2023:4076
SUSE-SU-2023:2849-1
SUSE-SU-2023:2850-1
SUSE-SU-2023:2886-1
USN-6201-1
USN-6214-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu