CVE-2021-38506: Medium severity thunderbird vulnerability
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing.
Other sources
Through a series of web navigations, Thunderbird could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38506.
What software is affected by this vulnerability?
This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
What is the severity of CVE-2021-38506?
The severity of CVE-2021-38506 is high.
How can this vulnerability be exploited?
This vulnerability can be exploited through a series of navigations, allowing Firefox to enter fullscreen mode without notification or warning to the user.
What is the impact of this vulnerability?
This vulnerability could lead to spoofing attacks on the browser UI, including phishing.