CVE-2021-38506
4.3
MEDIUM
CVSS 3.1
EPSS 0.86%
Description
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
How to fix CVE-2021-38506
To remediate CVE-2021-38506, upgrade the affected package to a fixed version below.
- Debian/firefox-esr—upgrade to 91.4.1esr-1~deb11u1 or later
- —upgrade to 1:91.4.1-1~deb11u1 or later
Is CVE-2021-38506 being exploited?
Low — EPSS is 0.9%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 91.4.1esr-1~deb11u1
- from 0, < 1:91.4.1-1~deb11u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |