CVE-2021-38492

When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

10 Aug 2022, 20:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202208-14 -

04 Nov 2021, 20:51

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References (MISC) https://www.mozilla.org/security/advisories/mfsa2021-41/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2021-41/ - Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2021-40/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2021-40/ - Vendor Advisory
References (MISC) https://bugzilla.mozilla.org/show_bug.cgi?id=1721107 - (MISC) https://bugzilla.mozilla.org/show_bug.cgi?id=1721107 - Permissions Required, Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2021-38/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2021-38/ - Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2021-42/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2021-42/ - Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2021-39/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2021-39/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.5
CWE NVD-CWE-noinfo

03 Nov 2021, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-11-03 01:15

Updated : 2024-10-21 13:55


NVD link : CVE-2021-38492

Mitre link : CVE-2021-38492

CVE.ORG link : CVE-2021-38492


JSON object : View

Products Affected

microsoft

  • windows

mozilla

  • firefox
  • firefox_esr
  • thunderbird