CVE-2023-4053
Mozilla: Full screen notification obscured by external program
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
Un sitio web podría haber oscurecido la notificación en pantalla completa utilizando una URL con un esquema manejado por un programa externo, como una URL de correo. Esto podría haber generado confusión en los usuarios y posibles ataques de suplantación de identidad. Esta vulnerabilidad afecta a Firefox < 116, Firefox ESR < 115.2 y Thunderbird < 115.2.
The Mozilla Foundation Security Advisory describes this flaw as:
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-08-01 CVE Reserved
- 2023-08-01 CVE Published
- 2024-09-02 EPSS Updated
- 2024-10-22 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- CWE-290: Authentication Bypass by Spoofing
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2023-36 | ||
https://www.mozilla.org/security/advisories/mfsa2023-38 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2023-29 | 2023-09-11 | |
https://access.redhat.com/security/cve/CVE-2023-4053 | 2023-09-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2236078 | 2023-09-07 |