CVE-2021-23995
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Affected (3)
Products: Mozilla: Firefox, Firefox Esr, Thunderbird
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 88.0 | |
| Before 78.10 | |
| Before 78.10 |
References (8)
Source: security@mozilla.org
Issue TrackingPermissions RequiredVendor Advisory
Source: security@mozilla.org
Release NotesVendor Advisory
Source: security@mozilla.org
Release NotesVendor Advisory
Source: security@mozilla.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Timeline
No history available yet.