The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
2024-08-06T13:15:57.657
2024-08-12T16:09:09.390
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 129.0 | Yes |
Application | mozilla | firefox_esr | < 115.14.0 | Yes |
Application | mozilla | firefox_esr | 128.0 | Yes |
Application | mozilla | thunderbird | < 115.14.0 | Yes |
Application | mozilla | thunderbird | 128.0.1 | Yes |