A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firefox-esr | Jun 28, 2021 | Jun 24, 2021 |
| Mfsa2021 10 | — | Upgrade to Mozilla Firefox version 87.0Upgrade to the latest version of Mozilla Firefox | Jun 9, 2021 | Mar 23, 2021 |
| Mfsa2021 11 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 78.9 | Jun 9, 2021 | Mar 23, 2021 |
| Oracle Solaris | — | Upgrade library/libmozjs-78 to version 78.11.0-11.4.39.0.1.107.0 on Solaris 11.4Upgrade web/browser/firefox to version 78.9.0-11.4.32.0.1.88.3 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 78.9.0-11.4.32.0.1.88.3 on Solaris 11.4 | Jul 21, 2021 | Jun 24, 2021 |
| Ubuntu | — | Upgrade firefox | Nov 19, 2024 | Jun 24, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub