CVE-2024-0750: High severity thunderbird vulnerability
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0750?
CVE-2024-0750 is considered a moderate severity vulnerability due to its potential to trick users into granting permissions.
How do I fix CVE-2024-0750?
To fix CVE-2024-0750, update your affected Mozilla products to the latest version, specifically 115.14.0esr or higher for Firefox ESR, and 134.0.2-2 for Debian's Firefox.
Which products are affected by CVE-2024-0750?
CVE-2024-0750 affects Mozilla Thunderbird up to version 115.7, Firefox ESR up to version 115.7, and Firefox up to version 122.
What kind of attack does CVE-2024-0750 enable?
CVE-2024-0750 enables an attacker to exploit popup notifications to trick users into granting inappropriate permissions.
Is there a workaround for CVE-2024-0750?
There is no official workaround for CVE-2024-0750, so upgrading to a secure version is the recommended approach.