We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-37207



Assignermozilla
Reserved2023-06-28
Published2023-07-05
Updated2024-11-20

Description

A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

Product status

Any version before 115
affected

Any version before 102.13
affected

Any version before 102.13
affected

Credits

Shaheen Fazim

References

https://bugzilla.mozilla.org/show_bug.cgi?id=1816287

https://www.mozilla.org/security/advisories/mfsa2023-22/

https://www.mozilla.org/security/advisories/mfsa2023-23/

https://www.mozilla.org/security/advisories/mfsa2023-24/

https://lists.debian.org/debian-lts-announce/2023/07/msg00006.html

https://www.debian.org/security/2023/dsa-5450

https://www.debian.org/security/2023/dsa-5451

https://lists.debian.org/debian-lts-announce/2023/07/msg00015.html

cve.org CVE-2023-37207

nvd.nist.gov CVE-2023-37207

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2023-37207
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.