CVE-2021-38501: High severity thunderbird vulnerability
Mozilla developers and community members Kevin Brosnan, Mihai Alexandru Michis, and Christian Holler reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
Mozilla developers and community members Kevin Brosnan, Mihai Alexandru Michis, and Christian Holler reported memory safety bugs present in Thunderbird 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2021-38501?
The severity of CVE-2021-38501 is high with a severity value of 8.8.
Which software versions are affected by CVE-2021-38501?
CVE-2021-38501 affects Firefox versions prior to 93, Thunderbird versions prior to 91.2, and Firefox ESR versions prior to 91.2.
How can CVE-2021-38501 be exploited?
CVE-2021-38501 can be exploited by running arbitrary code after exploiting memory corruption bugs in Firefox 92 and Firefox ESR 91.1.
Is there a fix available for CVE-2021-38501?
Yes, the fix for CVE-2021-38501 is available in Firefox version 93, Thunderbird version 91.2, and Firefox ESR version 91.2.
Where can I find more information about CVE-2021-38501?
You can find more information about CVE-2021-38501 on the Mozilla Security Advisories page at the following links: [https://www.mozilla.org/en-US/security/advisories/mfsa2021-47/](https://www.mozilla.org/en-US/security/advisories/mfsa2021-47/) and [https://www.mozilla.org/security/advisories/mfsa2021-43/](https://www.mozilla.org/security/advisories/mfsa2021-43/).