Rapid7

vulnerability

MFSA2021-28 Firefox: Security Vulnerabilities fixed in Firefox 90 (CVE-2021-29975)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Jul 13, 2021
Added
Jul 14, 2021
Modified
Mar 27, 2026

Description

Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion. This vulnerability affects Firefox < 90.

Solution

mozilla-firefox-upgrade-90_0
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.