CVE-2021-29970: Use After Free
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. This bug could only be triggered when accessibility was enabled.. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
Other sources
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. This bug only affected Firefox when accessibility was enabled.
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. This bug only affected Thunderbird when accessibility was enabled.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2021-29970?
CVE-2021-29970 is a vulnerability that could allow a malicious webpage to trigger a use-after-free memory corruption and a potentially exploitable crash.
Which software is affected by CVE-2021-29970?
Firefox ESR 78.12, Thunderbird 78.12, and Firefox up to version 90 are affected by CVE-2021-29970.
What is the severity of CVE-2021-29970?
CVE-2021-29970 has a severity rating of high.
How can I fix CVE-2021-29970?
To fix CVE-2021-29970, update your Firefox ESR to version 78.12, Thunderbird to version 78.12, or Firefox to a version beyond 90.
Where can I find more information about CVE-2021-29970?
You can find more information about CVE-2021-29970 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1709976), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2021-30/), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2021-28/).