216.73.217.22

CVE-2024-10458

· Published 29/10/2024 13:15 · Modified 31/10/2024 18:35

Labels: CVE-2024-10458 2024-10-29CVE-2024-10458CWE-281NVD-CWE-noinfo[email protected]

Essential information

Published
29/10/2024 13:15
Modified
31/10/2024 18:35
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

NVD status

Status
Modified — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mozilla / firefox cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
mozilla / firefox cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
mozilla / firefox cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
mozilla / thunderbird cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
mozilla / thunderbird cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

References