ZeroHour

CVE-2022-31738

CVSS 3.1
6.5 medium
EPSS
<1%p46
Published
()
Modified
Description

When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

Vendors
mozilla
Products
firefox, firefox esr, thunderbird
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.