CVE-2023-28159

The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
mozillaCNA
---
---
CVEADP
---
---
CISA-ADPADP
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
mozillafirefox
𝑥
< 111.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
firefox
sid
133.0.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
kinetic
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
ignored
trusty
ignored
mozjs38
kinetic
dne
jammy
dne
focal
dne
bionic
not-affected
xenial
dne
trusty
dne
mozjs52
kinetic
dne
jammy
dne
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
mozjs68
kinetic
dne
jammy
dne
focal
not-affected
bionic
dne
xenial
dne
trusty
dne
mozjs78
kinetic
not-affected
jammy
not-affected
focal
dne
bionic
dne
xenial
dne
trusty
dne
mozjs91
kinetic
dne
jammy
not-affected
focal
dne
bionic
dne
xenial
dne
trusty
dne
thunderbird
kinetic
ignored
jammy
needed
focal
needed
bionic
ignored
xenial
ignored
trusty
ignored