The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefox-esrUpgrade firefoxUpgrade librewolfUpgrade thunderbird | Aug 22, 2024 | Dec 8, 2021 |
| Mfsa2021 48 | — | Upgrade to Mozilla Firefox version 94.0Upgrade to the latest version of Mozilla Firefox | Nov 3, 2021 | Nov 2, 2021 |
| Mfsa2021 49 | — | Upgrade to Mozilla Firefox ESR version 91.3Upgrade to the latest version of Mozilla Firefox | Nov 3, 2021 | Nov 2, 2021 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 91.3 | Nov 4, 2021 | Nov 3, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 8, 2021 |
| Suse | — | Upgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-commonUpgrade MozillaThunderbird | Nov 11, 2021 | Nov 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub