CVE-2021-38509
Summary
| CVE | CVE-2021-38509 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-08 22:15:00 UTC |
| Updated | 2022-12-09 15:22:00 UTC |
| Description | Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Access Denied |
MISC |
bugzilla.mozilla.org |
|
| Debian -- Security Information -- DSA-5026-1 firefox-esr |
DEBIAN |
www.debian.org |
|
| Security Vulnerabilities fixed in Thunderbird 91.3 — Mozilla |
MISC |
www.mozilla.org |
|
| Mozilla Thunderbird: Multiple Vulnerabilities (GLSA 202208-14) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Security Vulnerabilities fixed in Firefox 94 — Mozilla |
MISC |
www.mozilla.org |
|
| Security Vulnerabilities fixed in Firefox ESR 91.3 — Mozilla |
MISC |
www.mozilla.org |
|
| Mozilla Firefox: Multiple vulnerabilities (GLSA 202202-03) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Debian -- Security Information -- DSA-5034-1 thunderbird |
DEBIAN |
www.debian.org |
|
| [SECURITY] [DLA 2863-1] firefox-esr security update |
MLIST |
lists.debian.org |
|
| [SECURITY] [DLA 2874-1] thunderbird security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159449 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-4116)
- 159450 Oracle Enterprise Linux Security Update for firefox (ELSA-2021-4123)
- 159451 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-4130)
- 159452 Oracle Enterprise Linux Security Update for thunderbird (ELSA-2021-4134)
- 178948 Debian Security Update for firefox-esr (DSA 5026-1)
- 178970 Debian Security Update for firefox-esr (DLA 2863-1)
- 178983 Debian Security Update for thunderbird (DSA 5034-1)
- 178986 Debian Security Update for thunderbird (DLA 2874-1)
- 180428 Debian Security Update for firefox-esr (CVE-2021-38509)
- 198556 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5131-1)
- 198581 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5152-1)
- 198641 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5248-1)
- 239773 Red Hat Update for firefox (RHSA-2021:4116)
- 239774 Red Hat Update for thunderbird (RHSA-2021:4133)
- 239775 Red Hat Update for thunderbird (RHSA-2021:4130)
- 239776 Red Hat Update for thunderbird (RHSA-2021:4134)
- 239777 Red Hat Update for firefox (RHSA-2021:4123)
- 239778 Red Hat Update for thunderbird (RHSA-2021:4132)
- 239853 Red Hat Update for firefox (RHSA-2021:4605)
- 239860 Red Hat Update for firefox (RHSA-2021:4607)
- 257117 CentOS Security Update for thunderbird (CESA-2021:4134)
- 257118 CentOS Security Update for firefox (CESA-2021:4116)
- 296066 Oracle Solaris 11.4 Support Repository Update (SRU) 40.107.3 Missing (CPUOCT2021)
- 376014 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2021-49)
- 376015 Mozilla Firefox Multiple Vulnerabilities (MFSA2021-48)
- 376038 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2021-50)
- 502070 Alpine Linux Security Update for firefox-esr
- 502082 Alpine Linux Security Update for firefox
- 502381 Alpine Linux Security Update for thunderbird
- 503632 Alpine Linux Security Update for thunderbird
- 503634 Alpine Linux Security Update for thunderbird
- 503650 Alpine Linux Security Update for thunderbird
- 503669 Alpine Linux Security Update for thunderbird
- 503853 Alpine Linux Security Update for firefox
- 506260 Alpine Linux Security Update for thunderbird
- 710574 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202202-03)
- 710585 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 202208-14)
- 751360 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3651-1)
- 751371 OpenSUSE Security Update for MozillaFirefox (openSUSE-SU-2021:3745-1)
- 751387 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2021:3721-1)
- 751542 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:4150-1)
- 751566 OpenSUSE Security Update for MozillaThunderbird (openSUSE-SU-2021:1635-1)
- 940017 AlmaLinux Security Update for thunderbird (ALSA-2021:4130)
- 940364 AlmaLinux Security Update for firefox (ALSA-2021:4123)
- 960054 Rocky Linux Security Update for firefox (RLSA-2021:4123)
- 960744 Rocky Linux Security Update for thunderbird (RLSA-2021:4130)