CVE-2021-29955
Description
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.
Risk Information
Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.884
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox ESR (x64) 78.8 | Windows |
| Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox ESR 78.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 78.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 86.99 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 78.8 | Windows |
| Multiple Vulnerabilities are affected in Mozilla_Firefox 86.99 | Windows |
| Vulnerabilities CVE-2021-29955 are affected in Firefox ESR for Mac 78.8 | Mac |
| Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox for Mac 78.8 | Mac |
| Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox for Mac 86.9 | Mac |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-611808 | Mozilla Firefox ESR for MAC 128.14.0 |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
| PATCH-611870 | Mozilla Firefox For Mac (142.0.1) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234