Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29948

Опубликовано: 24 июн. 2021
Источник: nvd
CVSS3: 2.5
CVSS2: 1.9
EPSS Низкий

Описание

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Версия до 78.10 (исключая)

EPSS

Процентиль: 22%
0.00071
Низкий

2.5 Low

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 2.5
ubuntu
около 4 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 2.5
redhat
больше 4 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 2.5
debian
около 4 лет назад

Signatures are written to disk before and read during verification, wh ...

github
около 3 лет назад

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replacing the file. This vulnerability affects Thunderbird < 78.10.

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость почтового клиента Thunderbird, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 22%
0.00071
Низкий

2.5 Low

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-362