CVE-2021-38506
Last modified
CVE-2021-38506 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | < 94.0 |
| Mozilla | Firefox Esr | < 91.3.0 |
| Mozilla | Thunderbird | < 91.3.0 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
| Debian | Debian Linux | 11.0 |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1730750Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00030.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00001.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202202-03Third Party Advisory
- https://security.gentoo.org/glsa/202208-14Third Party Advisory
- https://www.debian.org/security/2021/dsa-5026Third Party Advisory
- https://www.debian.org/security/2022/dsa-5034Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-48/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-49/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-50/Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1730750Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00030.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00001.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202202-03Third Party Advisory
- https://security.gentoo.org/glsa/202208-14Third Party Advisory
- https://www.debian.org/security/2021/dsa-5026Third Party Advisory
- https://www.debian.org/security/2022/dsa-5034Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-48/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-49/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2021-50/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-38506?
How severe is CVE-2021-38506?
How do I fix CVE-2021-38506?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-38500Mozilla developers reported memory safety bugs present in Fi…8.8
- CVE-2021-38501Mozilla developers reported memory safety bugs present in Fi…8.8
- CVE-2021-38502Thunderbird ignored the configuration to require STARTTLS se…5.9
- CVE-2021-38503The iframe sandbox rules were not correctly applied to XSLT …10
- CVE-2021-38504When interacting with an HTML input element's file picker di…8.8
- CVE-2021-38505Microsoft introduced a new feature in Windows 10 known as Cl…6.5
- CVE-2021-38507The Opportunistic Encryption feature of HTTP2 (RFC 8164) all…6.5
- CVE-2021-38508By displaying a form validity message in the correct locatio…4.3
- CVE-2021-38509Due to an unusual sequence of attacker-controlled events, a …4.3
- CVE-2021-3851firefly-iii is vulnerable to URL Redirection to Untrusted Si…5.4
- CVE-2021-38510The executable file warning was not presented when downloadi…8.8
- CVE-2021-38511An issue was discovered in the tar crate before 0.4.36 for R…7.5
Are you affected by CVE-2021-38506?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
