Fiche vulnérabilité
CVE-2021-38503 : faille critique mozilla firefox (CVSS 10.0)
Description
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
En bref
- Sévérité
- Critique (CVSS 10.0)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 8 déc. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- mozilla firefox
- mozilla firefox esr
- mozilla thunderbird
- debian debian linux
Références
- Fiche CVE-2021-38503 sur le NVD (NIST)
- bugzilla.mozilla.org/show_bug.cgi
- lists.debian.org/debian-lts-announce/2021/12/msg00030.html
- lists.debian.org/debian-lts-announce/2022/01/msg00001.html
- security.gentoo.org/glsa/202202-03
- security.gentoo.org/glsa/202208-14
- debian.org/security/2021/dsa-5026
- debian.org/security/2022/dsa-5034
- mozilla.org/security/advisories/mfsa2021-48/
- mozilla.org/security/advisories/mfsa2021-49/
- mozilla.org/security/advisories/mfsa2021-50/