Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9398


By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.


Published

2024-10-01T16:15:10.913

Last Modified

2025-03-18T20:15:25.150

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-203

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox < 131.0 Yes
Application mozilla firefox_esr < 128.3.0 Yes
Application mozilla thunderbird < 128.3 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes
Application mozilla thunderbird 129.0 Yes

References