KLA12193
Multiple vulnerabilities in Mozilla Firefox

Updated: 06/22/2021
Detect date
?
06/01/2021
Severity
?
High
Description

Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to bypass security restrictions, obtain sensitive information, spoof user interface, execute arbitrary code, cause denial of service.

Below is a complete list of vulnerabilities:

  1. A security bypass vulnerability in private browsing mode on Android can be exploited to bypass security restrictions.
  2. A spoofing vulnerability in password manager on Android can be exploited to perform domain spoofing and obtain sensitive information.
  3. A memory safety vulnerability can be exploited to execute arbitrary code.
  4. A security bypass vulnerability can be exploited to bypass security restrictions.
  5. A denial of service vulnerability in popups on Android can be exploited to cause denial of service.
  6. A security bypass vulnerability in private browsing mode can be exploited to bypass security restrictions.
  7. A security UI vulnerability can be exploited to spoof user interface.
  8. An out of bounds read vulnerability can be exploited to obtain sensitive information or cause denial of service.
Affected products

Mozilla Firefox earlier than 89

Solution

Update to the latest version
Download Firefox

Original advisories

MFSA2021-23

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

SUI 
[?]
Related products
Mozilla Firefox
CVE-IDS
?
KB list

5001963
5001946
5001944
5001955
5001953
5001943
5001956
5001939
5001934
5001954
5001945
5001947
5001962
4011698
5001950
5001922
5001942
5001951

Find out the statistics of the vulnerabilities spreading in your region