CVE-2021-29955

Description

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.884

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox ESR (x64) 78.8Windows
Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox ESR 78.8Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 78.8Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 86.99Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 78.8Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 86.99Windows
Vulnerabilities CVE-2021-29955 are affected in Firefox ESR for Mac 78.8Mac
Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox for Mac 78.8Mac
Vulnerabilities CVE-2021-29955 are affected in Mozilla Firefox for Mac 86.9Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-611808Mozilla Firefox ESR for MAC 128.14.0
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234