Mozilla Firefox
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*, +1 more
- < 139
A vulnerability exists in Firefox versions prior to 139 and Firefox ESR versions prior to 128.11, where script elements loading cross-origin resources could generate load and error events that leaked information. This leakage could be exploited to perform XS-Leaks attacks.
Exploitation of this vulnerability could lead to cross-site leakage attacks, allowing an attacker to gather information about the user's interactions with other sites.
Users can upgrade to Firefox 139 or Firefox ESR 128.11 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.