MEDIUM
The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes
Published Feb 26, 2021
6.5
MEDIUMCVSS 3.1
EPSS 1.01%
Description
The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.
Affected products
-
- Version < 86StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://bugzilla.mozilla.org/show_bug.cgi?id=1685145 x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-10896 Advisory
- https://security.gentoo.org/glsa/202104-10 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-07/ x_refsource_MISCRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.mozilla.org/show_bug.cgi?id=1685145 | x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-10896 | Advisory | |
| https://security.gentoo.org/glsa/202104-10 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2021-07/ | x_refsource_MISCRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Feb 26, 2021
Updated Aug 3, 2024
Reserved Jan 13, 2021
Link CVE-2021-23975
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-10896 Assigner mozilla
Published Feb 26, 2021
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2021-10896