CVE-2024-0749: Medium severity thunderbird vulnerability
A phishing site could have repurposed an about: dialog to show phishing content with an incorrect origin in the address bar.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0749
Other sources
A phishing site could have repurposed an about: dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
— Launchpad
A phishing site could have repurposed an about: dialog to show phishing content with an incorrect origin in the address bar.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0749?
CVE-2024-0749 has been classified as a moderate severity vulnerability due to its potential for exploitation through phishing attacks.
How do I fix CVE-2024-0749?
To remediate CVE-2024-0749, update your Mozilla Thunderbird or Firefox ESR to versions above 115.7 or the latest stable release.
Which versions of Thunderbird are affected by CVE-2024-0749?
CVE-2024-0749 affects Mozilla Thunderbird versions prior to 115.7.
Can CVE-2024-0749 affect users of Firefox ESR?
Yes, CVE-2024-0749 impacts Firefox ESR versions up to and including 115.7.
What type of attacks can exploit CVE-2024-0749?
CVE-2024-0749 can be exploited to deliver phishing content by manipulating the address bar to show an incorrect origin.