CVE-2021-23978
CVE-2021-23978
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 1.5%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
26 feb 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://bugzilla.mozilla.org/buglist.cgi?bug_id=786797%2C1682928%2C1687391%2C1687597https://lists.debian.org/debian-lts-announce/2021/03/msg00000.htmlhttps://security.gentoo.org/glsa/202104-09https://security.gentoo.org/glsa/202104-10https://www.debian.org/security/2021/dsa-4866https://www.mozilla.org/security/advisories/mfsa2021-07/https://www.mozilla.org/security/advisories/mfsa2021-08/https://www.mozilla.org/security/advisories/mfsa2021-09/