|
194941
|
8.8 |
HIGH
Network
|
mozilla
|
firefox thunderbird firefox_esr
|
Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-23987
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194942
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read…
|
CWE-346
Origin Validation Error
|
CVE-2021-23986
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194943
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird firefox_esr
|
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could ha…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2021-23984
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194944
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vul…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-23983
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194945
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird firefox_esr
|
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRT…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2021-23982
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194946
|
8.1 |
HIGH
Network
|
mozilla
|
firefox thunderbird firefox_esr
|
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information lea…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-23981
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194947
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unno…
|
NVD-CWE-Other
|
CVE-2021-23985
|
2024-11-21 14:52 |
2021-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194948
|
4.8 |
MEDIUM
Network
|
mcafee
|
epolicy_orchestrator
|
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the admi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-23889
|
2024-11-21 14:52 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194949
|
6.3 |
MEDIUM
Network
|
mcafee
|
epolicy_orchestrator
|
Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which …
|
CWE-601
Open Redirect
|
CVE-2021-23888
|
2024-11-21 14:52 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194950
|
6.5 |
MEDIUM
Network
|
mcafee
|
epolicy_orchestrator
|
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfe…
|
CWE-200
Information Exposure
|
CVE-2021-23890
|
2024-11-21 14:52 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|