Show filters
185 Total Results
Displaying 41-50 of 185
Sort by:
Attacker Value
Unknown

CVE-2021-43541

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43539

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43538

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43537

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43536

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43535

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
Attacker Value
Unknown

CVE-2021-43534

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Attacker Value
Unknown

CVE-2021-43528

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.
Attacker Value
Unknown

CVE-2021-38509

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Attacker Value
Unknown

CVE-2021-38508

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.