CVE-2024-8386: Medium severity thunderbird vulnerability
Published Sep 3, 2024
·Updated
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack.
Affected Software
7 affected componentsFixes available
debian/firefox
131.0.2-2
debian/thunderbird
1:115.12.0-1~deb11u11:115.16.0esr-1~deb11u11:115.12.0-1~deb12u11:115.16.0esr-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<128.2
128.2
Mozilla Firefox<130
130
Mozilla Firefox<130.0
Mozilla Firefox ESR<128.2
Mozilla Firefox ESR<128.2
128.2
Event History
Sep 3, 2024
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
DescriptionWeakness
Data Sourced
via Red Hat·01:20 PM
DescriptionSeverityAffected Software
Sep 17, 2024
Data Sourced
via Ubuntu·03:24 AM
RemedyDescriptionSeverityAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What should I do if I cannot update due to compatibility issues related to CVE-2024-8386?
If you cannot update due to compatibility issues, consider using alternative software until a patch is available or seek guidance from your IT department.