CVE-2024-11700 Vulnerability Details

  /     /     /  

CVE-2024-11700 Metadata Quick Info

CVE Published: 26/11/2024 | CVE Updated: 02/12/2024 | CVE Year: 2024
Source: mozilla | Vendor: Mozilla | Product: Firefox
Status : PUBLISHED

CVE-2024-11700 Description

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Potential Tapjacking Exploit for Intent Confirmation on Android
Source: Mozilla

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).