CVE-2021-23964 describes multiple memory safety bugs in Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 85, 78.7, and 78.7 respectively. These vulnerabilities, rated 8.8 HIGH, could lead to arbitrary code execution due to memory corruption, requiring user interaction for exploitation over a network. While no active exploitation or public exploit code is known, the potential for high impact on confidentiality, integrity, and availability is significant. Community discussion and media coverage are minimal, suggesting low public awareness despite the high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 85.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 78.7CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 78.7CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.