CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.1. It affects Firefox. It is listed in CISA's Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild.
CISA KEV Details
Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Ransomware use: Unknown
Added to KEV: 2021-11-03
Required action: Apply updates per vendor instructions.
Original NVD Description
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)