CVE-2021-38492

Source
https://cve.org/CVERecord?id=CVE-2021-38492
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-38492.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-38492
Downstream
Related
Published
2021-11-03T01:15:07.200Z
Modified
2026-03-15T22:41:29.828163Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

When delegating navigations to the operating system, Firefox would accept the mk scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. This bug only affects Firefox for Windows. Other operating systems are unaffected.. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 78.14, Firefox ESR < 78.14, and Firefox ESR < 91.1.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-38492.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "92.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "91.0"
            },
            {
                "fixed": "91.1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "78.14"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "78.14"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "91.0"
            },
            {
                "fixed": "91.1"
            }
        ]
    }
]