Vulnerabilities > Mozilla > Thunderbird > 91.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-08 | CVE-2021-38506 | Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. | 4.3 |
2021-12-08 | CVE-2021-38507 | Origin Validation Error vulnerability in multiple products The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. | 6.5 |
2021-12-08 | CVE-2021-38508 | Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. | 4.3 |
2021-12-08 | CVE-2021-38509 | Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. | 4.3 |
2021-12-08 | CVE-2021-38510 | Unspecified vulnerability in Mozilla Firefox The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. | 8.8 |
2021-12-08 | CVE-2021-43528 | Improper Privilege Management vulnerability in multiple products Thunderbird unexpectedly enabled JavaScript in the composition area. | 6.5 |
2021-12-08 | CVE-2021-43534 | Out-of-bounds Write vulnerability in multiple products Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. | 8.8 |
2021-12-08 | CVE-2021-43535 | Use After Free vulnerability in multiple products A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. | 8.8 |
2021-12-08 | CVE-2021-43536 | Information Exposure vulnerability in multiple products Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. | 6.5 |
2021-12-08 | CVE-2021-43537 | Incorrect Type Conversion or Cast vulnerability in multiple products An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. | 8.8 |