CVE-2021-4127
published 2022-12-22CVE-2021-4127: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and…
PriorityP343critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.90%
55.7th percentile
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox-esr | < firefox-esr 78.9.0esr-1 (bookworm) | firefox-esr 78.9.0esr-1 (bookworm) |
| debian | thunderbird | < firefox-esr 78.9.0esr-1 (bookworm) | firefox-esr 78.9.0esr-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | < 78.9.0 | 78.9.0 |
| mozilla | firefox_esr | >= unspecified < 78.9 | 78.9 |
| mozilla | thunderbird | < 78.9.0 | 78.9.0 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= 0 < 1:78.9.0-1 | 1:78.9.0-1 |
| mozilla | thunderbird | >= unspecified < 78.9 | 78.9 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Mozilla: Angle graphics library out of date
vendor_redhat·2021-03-23·CVSS 9.8
CVE-2021-4127 [CRITICAL] CWE-119 Mozilla: Angle graphics library out of date
Mozilla: Angle graphics library out of date
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
The Mozilla Foundation Security Advisory describes this issue as:
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: thunderbird (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2021-4127: firefox-esr - An out of date graphics library (Angle) likely contained vulnerabilities that co...
vendor_debian·2021·CVSS 9.8
CVE-2021-4127 [CRITICAL] CVE-2021-4127: firefox-esr - An out of date graphics library (Angle) likely contained vulnerabilities that co...
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
Scope: local
bookworm: resolved (fixed in 78.9.0esr-1)
bullseye: resolved (fixed in 78.9.0esr-1)
forky: resolved (fixed in 78.9.0esr-1)
sid: resolved (fixed in 78.9.0esr-1)
trixie: resolved (fixed in 78.9.0esr-1)
Mozilla
Mozilla Foundation Security Advisory 2021-12: CVE-2021-4127
vendor_mozilla·CVSS 9.8
CVE-2021-4127 [CRITICAL] Mozilla Foundation Security Advisory 2021-12: CVE-2021-4127
Mozilla Foundation Security Advisory 2021-12
CVE: CVE-2021-4127
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.9
Mozilla
Mozilla Foundation Security Advisory 2021-11: CVE-2021-4127
vendor_mozilla·CVSS 9.8
CVE-2021-4127 [CRITICAL] Mozilla Foundation Security Advisory 2021-11: CVE-2021-4127
Mozilla Foundation Security Advisory 2021-11
CVE: CVE-2021-4127
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.9
GHSA
GHSA-7wp9-fj5q-c4jc: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited
ghsa_unreviewed·2022-12-22
CVE-2021-4127 [CRITICAL] GHSA-7wp9-fj5q-c4jc: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
OSV
CVE-2021-4127: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited
osv·2022-12-22·CVSS 9.8
CVE-2021-4127 [CRITICAL] CVE-2021-4127: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1691547https://www.mozilla.org/security/advisories/mfsa2021-11/https://www.mozilla.org/security/advisories/mfsa2021-12/https://bugzilla.mozilla.org/show_bug.cgi?id=1691547https://www.mozilla.org/security/advisories/mfsa2021-11/https://www.mozilla.org/security/advisories/mfsa2021-12/
2022-12-22
Published