← Back

CVE-2021-29955

nvd nist
Published: Jun 24, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD

Description

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.

Affected (2)

2 products
Firefox
Firefox Esr
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 87.0
Before 78.9

References (6)

Source: security@mozilla.org
Permissions RequiredVendor Advisory
Source: security@mozilla.org
Release NotesVendor Advisory
Source: security@mozilla.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.