Aller au contenu

Fiche vulnérabilité

CVE-2021-38503 : faille critique mozilla firefox (CVSS 10.0)

Description

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

En bref

Sévérité
Critique (CVSS 10.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
8 déc. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • mozilla firefox
  • mozilla firefox esr
  • mozilla thunderbird
  • debian debian linux

Références

Rechercher une autre vulnérabilité dans la base CVE