CVE-2024-6608

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:49

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1743329 - Issue Tracking () https://bugzilla.mozilla.org/show_bug.cgi?id=1743329 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2024-29/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2024-29/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-32/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2024-32/ - Vendor Advisory

29 Aug 2024, 18:34

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1743329 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1743329 - Issue Tracking
References () https://www.mozilla.org/security/advisories/mfsa2024-29/ - () https://www.mozilla.org/security/advisories/mfsa2024-29/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-32/ - () https://www.mozilla.org/security/advisories/mfsa2024-32/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
First Time Mozilla firefox
Mozilla thunderbird
Mozilla

16 Jul 2024, 18:15

Type Values Removed Values Added
References
  • () https://www.mozilla.org/security/advisories/mfsa2024-32/ -
Summary
  • (es) Era posible mover el cursor usando el bloqueo del puntero desde un iframe. Esto permitió mover el cursor fuera de la ventana gráfica y de la ventana de Firefox. Esta vulnerabilidad afecta a Firefox &lt; 128.
Summary (en) It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128. (en) It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.

09 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 15:15

Updated : 2024-11-21 09:49


NVD link : CVE-2024-6608

Mitre link : CVE-2024-6608

CVE.ORG link : CVE-2024-6608


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox