Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +1 more
- < 139
A vulnerability exists in Firefox versions prior to 139, Firefox ESR versions prior to 115.24, and Firefox ESR 128.10, due to improper isolation of error handling for script execution from web content. This flaw could have facilitated cross-origin leak attacks.
Exploitation of this vulnerability could have allowed cross-origin leak attacks, enabling the unauthorized transfer of information between different origins.
Users can upgrade to Firefox 139, Firefox ESR 115.24, or Firefox ESR 128.11 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.