Vulnerabilities > CVE-2021-23994 - Missing Initialization of Resource vulnerability in Mozilla Thunderbird

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
mozilla
CWE-909

Summary

A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

Vulnerable Configurations

Part Description Count
Application
Mozilla
1296

Common Weakness Enumeration (CWE)