CVE-2021-23997: Use After Free
Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effort this could have been exploited to run arbitrary code.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-23997?
CVE-2021-23997 has a moderate severity rating due to the potential for exploitation leading to arbitrary code execution.
How do I fix CVE-2021-23997?
To fix CVE-2021-23997, update Mozilla Firefox to version 88 or later.
What versions of Firefox are affected by CVE-2021-23997?
CVE-2021-23997 affects all versions of Mozilla Firefox prior to version 88.
Can CVE-2021-23997 be exploited remotely?
Yes, CVE-2021-23997 could potentially be exploited remotely through crafted web content.
What is a use-after-free vulnerability in the context of CVE-2021-23997?
A use-after-free vulnerability like CVE-2021-23997 occurs when memory that has been freed is accessed, potentially leading to arbitrary code execution.