Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 135
A vulnerability exists in Firefox versions prior to 135 and Thunderbird versions prior to 135, allowing the z-order of browser windows to be manipulated. This manipulation can hide the fullscreen notification, potentially leading to a spoofing attack.
Exploitation of this vulnerability could result in a spoofing attack, where a user is misled or deceived by the content being presented to them.
Users can upgrade to Firefox 135 or Thunderbird 135 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.