CVE-2024-2609

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

01 Apr 2025, 17:19

Type Values Removed Values Added
First Time Debian
Mozilla firefox
Mozilla
Mozilla thunderbird
Debian debian Linux
CPE cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1866100 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1866100 - Issue Tracking, Exploit, Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html - Mailing List
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00013.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00013.html - Mailing List
References () https://www.mozilla.org/security/advisories/mfsa2024-12/ - () https://www.mozilla.org/security/advisories/mfsa2024-12/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-19/ - () https://www.mozilla.org/security/advisories/mfsa2024-19/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2024-20/ - () https://www.mozilla.org/security/advisories/mfsa2024-20/ - Vendor Advisory

14 Mar 2025, 20:15

Type Values Removed Values Added
CWE CWE-356

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1866100 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1866100 -
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html -
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00013.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00013.html -
References () https://www.mozilla.org/security/advisories/mfsa2024-12/ - () https://www.mozilla.org/security/advisories/mfsa2024-12/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-19/ - () https://www.mozilla.org/security/advisories/mfsa2024-19/ -
References () https://www.mozilla.org/security/advisories/mfsa2024-20/ - () https://www.mozilla.org/security/advisories/mfsa2024-20/ -

28 Aug 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

22 Apr 2024, 10:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00013.html -

19 Apr 2024, 17:15

Type Values Removed Values Added
Summary (en) The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124 and Firefox ESR < 115.10. (en) The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
References
  • () https://www.mozilla.org/security/advisories/mfsa2024-20/ -

19 Apr 2024, 11:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00012.html -

19 Mar 2024, 13:26

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-19 12:15

Updated : 2025-04-01 17:19


NVD link : CVE-2024-2609

Mitre link : CVE-2024-2609

CVE.ORG link : CVE-2024-2609


JSON object : View

Products Affected

debian

  • debian_linux

mozilla

  • thunderbird
  • firefox
CWE
CWE-356

Product UI does not Warn User of Unsafe Actions