CVE-2024-11701

MEDIUM

Firefox < 133 and Thunderbird < 133 - Authentication Bypass by Spoofing via Address Bar Display

Title source: llm
STIX 2.1

Description

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.

Scores

CVSS v3 4.3
EPSS 0.0039
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (2)
mozilla/firefox < 133.0
mozilla/thunderbird < 133.0
Published Nov 26, 2024
Tracked Since Feb 18, 2026