Related Vulnerabilities: CVE-2021-23978  

A security issue was found in Firefox before version 86.0 and Thunderbird before version 78.8. Mozilla developers reported memory safety bugs present in Firefox 85, Firefox ESR 78.7 and Thunderbird 78.7. Some of these bugs showed evidence of memory corruption and Mozilla presumes that with enough effort some of these could have been exploited to run arbitrary code.

Severity High

Remote Yes

Type Arbitrary code execution

Description

A security issue was found in Firefox before version 86.0 and Thunderbird before version 78.8. Mozilla developers reported memory safety bugs present in Firefox 85, Firefox ESR 78.7 and Thunderbird 78.7. Some of these bugs showed evidence of memory corruption and Mozilla presumes that with enough effort some of these could have been exploited to run arbitrary code.

AVG-1601 thunderbird 78.7.1-1 High Vulnerable

AVG-1599 firefox 85.0.2-1 86.0-1 High Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2021-07/#CVE-2021-23978
https://www.mozilla.org/en-US/security/advisories/mfsa2021-09/#CVE-2021-23978
https://bugzilla.mozilla.org/buglist.cgi?bug_id=786797%2C1682928%2C1687391%2C1687597