CVE-2021-23995: Use After Free
When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-23995?
CVE-2021-23995 is a vulnerability in Mozilla Thunderbird and Firefox that could allow an attacker to run arbitrary code.
Which software versions are affected by CVE-2021-23995?
Mozilla Thunderbird 78.10, Mozilla Firefox ESR 78.10, and Mozilla Firefox up to version 88 are affected by CVE-2021-23995.
How severe is CVE-2021-23995?
CVE-2021-23995 has a severity rating of 7, which is considered high.
How can CVE-2021-23995 be exploited?
CVE-2021-23995 can be exploited by enabling Responsive Design Mode and using references to freed objects.
Are there any references for more information about CVE-2021-23995?
Yes, you can find more information about CVE-2021-23995 in the following references: [Link 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1699835), [Link 2](https://www.mozilla.org/en-US/security/advisories/mfsa2021-14/), [Link 3](https://www.mozilla.org/en-US/security/advisories/mfsa2021-16/).