Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*
- < 144
A vulnerability exists in Mozilla Firefox versions prior to 144, Firefox ESR versions prior to 140.4, Thunderbird versions prior to 144, and Thunderbird ESR versions prior to 140.4. A malicious page could exploit the type attribute of an OBJECT tag to alter the default browser behavior when handling web resources that lack a content-type. This manipulation could have facilitated a cross-site scripting (XSS) attack on websites that improperly serve files without a content-type header.
Exploitation of this vulnerability could have led to a cross-site scripting (XSS) attack on affected sites.
Users can upgrade to Firefox 144, Firefox ESR 140.4, Thunderbird 144, or Thunderbird ESR 140.4 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.