CVE-2024-9398Medium· 5.3▾ SunlitBy checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firef…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
By checking the result of calls to window.open with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
firefox < 128.3.0firefox < 131.0thunderbird < 128.3thunderbird = 129.0Upgrade past the affected range:
firefox 131.0thunderbird 128.3Connected by shared product, vendor, weakness, or advisory.
CVE-2020-12401Medium· 4.7During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data
CVE-2020-12400Medium· 4.7When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack
CVE-2026-106016Critical· 9.8Mitigation bypass in the File Handling component
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100832High· 8.8Use-after-free in the Graphics: Canvas2D component
CVE-2026-100831High· 8.8Use-after-free in the DOM: UI Events & Focus Handling component