The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade firefoxUpgrade librewolfUpgrade thunderbirdUpgrade firefox-esr | Aug 22, 2024 | Dec 8, 2021 |
| Mfsa2021 48 | — | Upgrade to Mozilla Firefox version 94.0Upgrade to the latest version of Mozilla Firefox | Nov 3, 2021 | Nov 2, 2021 |
| Mfsa2021 49 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 91.3 | Nov 3, 2021 | Nov 2, 2021 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.3Upgrade to the latest version of Mozilla Thunderbird | Nov 4, 2021 | Nov 3, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 8, 2021 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade mozillafirefox-branding-upstreamUpgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-translations-other | Nov 11, 2021 | Nov 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub