CVE-2021-29964

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
24/06/2021
Last modified:
30/06/2021

Description

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 89.0 (excluding)
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* 78.11 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 78.11 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*