CVE-2024-11695
MEDIUMFirefox < 133 & Thunderbird < 128.5 - Open Redirect
Title source: llmDescription
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
References (6)
Scores
CVSS v3
5.4
EPSS
0.0016
EPSS Percentile
36.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1021
Status
published
Products (3)
mozilla/firefox
< 128.5.0
mozilla/firefox
< 133.0
mozilla/thunderbird
< 128.5.0
Published
Nov 26, 2024
Tracked Since
Feb 18, 2026