A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
2021-06-24T14:15:10.333
2024-11-21T06:02:04.413
Modified
CVSSv3.1: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 89.0 | Yes |
Application | mozilla | firefox_esr | < 78.11 | Yes |
Application | mozilla | thunderbird | < 78.11 | Yes |
Operating System | microsoft | windows | - | No |