cbcvebase.
CVE-2021-29958
published 2021-06-24

CVE-2021-29958: When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in…

PriorityP416medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.67%
47.9th percentile
When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookies being shared in normal browsing mode. This vulnerability affects Firefox for iOS < 34.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianfirefox
mozillafirefox< 34.034.0
mozillafirefox
mozillafirefox_for_ios>= unspecified < 3434

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.