CVE-2024-8383
HIGHDescription
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.
Is your site exposed to CVE-2024-8383?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mozilla | firefox |
| mozilla | firefox_esr |
| mozilla | firefox_esr |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-8383? +
How severe is CVE-2024-8383? +
What products are affected by CVE-2024-8383? +
How do I check if I'm vulnerable to CVE-2024-8383? +
Related Vulnerabilities
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when …
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default …
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by …
A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific …
Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the …
A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel …