High severity8.8NVD Advisory· Published Aug 5, 2021· Updated Jun 17, 2026
CVE-2021-29972
CVE-2021-29972
Description
A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. This vulnerability affects Firefox < 90.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5<90+ 2 more
- (no CPE)range: <90
- (no CPE)range: unspecified
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <90.0
- osv-coords2 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 92.0-1.2+ 1 more
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 128.5.1-1.1
Patches
Vulnerability mechanics
References
3- bugzilla.mozilla.org/show_bug.cginvdExploitIssue TrackingVendor Advisory
- security.gentoo.org/glsa/202202-03nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2021-28/nvdVendor Advisory
News mentions
0No linked articles in our index yet.