CVE-2021-29964
Summary
| CVE | CVE-2021-29964 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 14:15:00 UTC |
| Updated | 2021-06-30 20:56:00 UTC |
| Description | A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296053 Oracle Solaris 11.4 Support Repository Update (SRU) 35.94.4 Missing (CPUJUL2021)
- 375606 Mozilla Firefox Multiple Vulnerabilities (MFSA2021-23)
- 375607 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-24)
- 375609 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-26)
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 506260 Alpine Linux Security Update for thunderbird
- 630721 Mozilla Firefox For Android Multiple Vulnerabilities
- 750119 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:1884-1)
- 750123 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:1886-1)
- 750141 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:1919-1)
- 750166 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:0858-1)
- 750714 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:0910-1)
- 750815 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:2003-1)
- 750823 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:1884-1)