CVE-2021-38492
- EPSS 0.44%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:14
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other ope...
CVE-2021-38493
- EPSS 0.33%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:14
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. ...
CVE-2021-38495
- EPSS 0.44%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:14
Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerab...
CVE-2021-38496
- EPSS 1.09%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:14
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, ...
CVE-2021-38497
- EPSS 0.2%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:14
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and F...
CVE-2021-38498
- EPSS 0.36%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:15
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91....
CVE-2021-38500
- EPSS 1.94%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:15
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...
CVE-2021-38501
- EPSS 0.88%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:15
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...
CVE-2021-38502
- EPSS 0.46%
- Veröffentlicht 03.11.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:15
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to execute SMTP commands chosen b...
CVE-2021-40529
- EPSS 0.28%
- Veröffentlicht 06.09.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:20
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the rece...