4.3
CVE-2021-43546
- EPSS 1.4%
- Veröffentlicht 08.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:29:24
- Erkennungen
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox ESR Version < 91.4.0
Mozilla ≫ Thunderbird Version < 91.4.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.4% | 0.69 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://security.gentoo.org/glsa/202202-03
https://security.gentoo.org/glsa/202208-14
https://lists.debian.org/debian-lts-announce/2022/01/msg00001.html
https://www.debian.org/security/2022/dsa-5034
https://lists.debian.org/debian-lts-announce/2021/12/msg00030.html
https://www.debian.org/security/2021/dsa-5026
https://www.mozilla.org/security/advisories/mfsa2021-54/
https://www.mozilla.org/security/advisories/mfsa2021-52/
https://www.mozilla.org/security/advisories/mfsa2021-53/
https://bugzilla.mozilla.org/show_bug.cgi?id=1737751