Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-29955

Опубликовано: 24 июн. 2021
Источник: debian

Описание

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed87.0-1package
firefox-esrfixed78.9.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-10/#CVE-2021-29955

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-11/#CVE-2021-29955

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 5 лет назад

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.

CVSS3: 5.3
nvd
около 5 лет назад

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.

github
около 4 лет назад

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.

CVSS3: 5.3
fstec
больше 5 лет назад

Уязвимость веб-браузеров Firefox ESR и Firefox, связанная с недостаточной нейтрализацией специальных элементов в запросе, позволяющая нарушителю получить доступ к конфиденциальным данным