Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-38498

Опубликовано: 03 нояб. 2021
Источник: debian
EPSS Низкий

Описание

During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed93.0-1package
firefox-esrnot-affectedpackage
thunderbirdnot-affectedpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-43/#CVE-2021-38498

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-45/#CVE-2021-38498

  • https://www.mozilla.org/en-US/security/advisories/mfsa2021-47/#CVE-2021-38498

EPSS

Процентиль: 66%
0.00523
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.

CVSS3: 7.5
redhat
почти 4 года назад

During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.

CVSS3: 7.5
nvd
почти 4 года назад

During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.

github
около 3 лет назад

During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.

CVSS3: 8.8
fstec
почти 4 года назад

Уязвимость объекта nsLanguageAtomService браузеров Mozilla Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 66%
0.00523
Низкий