CVE-2021-38496
CVE-2021-38496
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
03 Nov 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://bugzilla.mozilla.org/show_bug.cgi?id=1725335https://lists.debian.org/debian-lts-announce/2022/01/msg00001.htmlhttps://www.debian.org/security/2022/dsa-5034https://www.mozilla.org/security/advisories/mfsa2021-43/https://www.mozilla.org/security/advisories/mfsa2021-44/https://www.mozilla.org/security/advisories/mfsa2021-45/https://www.mozilla.org/security/advisories/mfsa2021-46/https://www.mozilla.org/security/advisories/mfsa2021-47/