CVE-2021-43544
Description
When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.
Risk Information
Base Score
6.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.38
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities fixed in Mozilla Firefox (95.0) | Windows |
| Multiple vulnerabilities fixed in Mozilla Firefox (x64) (95.0) | Windows |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (95.0) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (95.0.1) | Mac |
| Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (95.0.2) | Mac |
| Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 94.0 | Mac |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-322722 | Mozilla Firefox (95.0) |
| PATCH-322723 | Mozilla Firefox (x64) (95.0) |
| PATCH-607000 | Mozilla Firefox For Mac (124.0) |
| PATCH-607000 | Mozilla Firefox For Mac (124.0) |
| PATCH-607000 | Mozilla Firefox For Mac (124.0) |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234