CVE-2021-23960: High severity thunderbird vulnerability
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-23960?
CVE-2021-23960 is classified as a high-severity vulnerability due to the potential for user-after-poison exploitation leading to a crash.
How do I fix CVE-2021-23960?
To resolve CVE-2021-23960, upgrade affected applications to versions newer than 78.7 for Thunderbird or 85 for Firefox.
Which software is affected by CVE-2021-23960?
CVE-2021-23960 affects Mozilla Thunderbird versions up to 78.7, Firefox versions up to 85, and Firefox ESR versions up to 78.7.
What is the impact of CVE-2021-23960 on users?
Users of vulnerable software may experience crashes and could be exposed to potential exploit scenarios due to unhandled JavaScript variables.
Is CVE-2021-23960 being actively exploited?
There have been reports suggesting that CVE-2021-23960 may be exploited in the wild, which emphasizes the importance of updating affected applications promptly.