Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2021-23991

CVE-2021-23991, medium severity (CVSS 6.8): 1 tracked app concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
6.8

NVD scale

Exploitation
1.0 %

EPSS, predicted over 30 days

Tracked apps
1
Still exposed
0

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet been imported, an attacker may send an email containing a crafted version of Alice's key with an invalid subkey, Thunderbird might subsequently attempt to use the invalid subkey, and will fail to send encrypted email to Alice. This vulnerability affects Thunderbird < 78.9.1.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS 1.04% above median percentile 62.5%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (1)
Vendor Product Versions
mozilla thunderbird
All platforms (wildcard)
<78.9.1
View on NVD ↗ Advisory · bugzilla.mozilla.org Advisory · www.mozilla.org

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM