By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
2024-06-11T13:15:50.553
2025-03-26T14:15:31.660
Modified
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 127.0 | Yes |
| Application | mozilla | firefox_esr | < 115.12 | Yes |
| Application | mozilla | thunderbird | < 115.12 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |