Related Vulnerabilities: CVE-2021-23981  

A security issue was found in Firefox before version 87 and Thunderbird before version 78.9. A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash.

Severity High

Remote Yes

Type Arbitrary code execution

Description

A security issue was found in Firefox before version 87 and Thunderbird before version 78.9. A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash.

AVG-1729 thunderbird 78.8.1-1 High Vulnerable

AVG-1728 firefox 86.0.1-1 87.0-1 High Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2021-10/#CVE-2021-23981
https://www.mozilla.org/en-US/security/advisories/mfsa2021-12/#CVE-2021-23981
https://bugzilla.mozilla.org/show_bug.cgi?id=1692832