CVE Vulnerabilities

CVE-2021-38492

Published: Nov 03, 2021 | Modified: Dec 09, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

When delegating navigations to the operating system, Firefox would accept the mk scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 92.0 (excluding)
Firefox_esr Mozilla * 78.14 (excluding)
Firefox_esr Mozilla 91.0 (including) 91.1 (excluding)
Thunderbird Mozilla * 78.14 (excluding)
Thunderbird Mozilla 91.0 (including) 91.1 (excluding)

References