When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
History

Tue, 26 Nov 2024 13:45:00 +0000

Type Values Removed Values Added
Description When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2024-11-26T13:33:59.551Z

Updated: 2024-11-26T13:33:59.551Z

Reserved: 2024-11-25T16:29:35.260Z

Link: CVE-2024-11697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2024-11-26T14:15:19.243

Modified: 2024-11-26T14:15:19.243

Link: CVE-2024-11697

cve-icon Redhat

No data.