Show filters
1,460 Total Results
Displaying 391-400 of 1,460
Sort by:
Attacker Value
Unknown
CVE-2021-38501
Disclosure Date: November 03, 2021 (last updated November 28, 2024)
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
0
Attacker Value
Unknown
CVE-2021-38495
Disclosure Date: November 03, 2021 (last updated February 23, 2025)
Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.1 and Firefox ESR < 91.1.
0
Attacker Value
Unknown
CVE-2021-38492
Disclosure Date: November 03, 2021 (last updated October 22, 2024)
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
0
Attacker Value
Unknown
CVE-2021-38497
Disclosure Date: November 03, 2021 (last updated February 23, 2025)
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
0
Attacker Value
Unknown
CVE-2021-40529
Disclosure Date: September 06, 2021 (last updated February 23, 2025)
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
0
Attacker Value
Unknown
CVE-2021-29986
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
0
Attacker Value
Unknown
CVE-2021-29981
Disclosure Date: August 17, 2021 (last updated November 28, 2024)
An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a potentially exploitable crash. This vulnerability affects Firefox < 91 and Thunderbird < 91.
0
Attacker Value
Unknown
CVE-2021-29985
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
0
Attacker Value
Unknown
CVE-2021-29987
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible to trick a user into accepting a permission they did not want to. *This bug only affects Firefox on Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91 and Thunderbird < 91.
0
Attacker Value
Unknown
CVE-2021-29980
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
0