CVE-2024-11701: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.

Affected products

  • Mozilla Firefox: before 133.0 (fixed in 133.0)
  • Mozilla Thunderbird: before 133.0 (fixed in 133.0)

Published 2024-11-26. Last modified 2026-06-17.