Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-34470

Опубликовано: 22 дек. 2022
Источник: debian
EPSS Низкий

Описание

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed102.0-1package
firefox-esrfixed91.11.0esr-1package
thunderbirdfixed1:91.11.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-24/#CVE-2022-34470

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-25/#CVE-2022-34470

  • https://www.mozilla.org/en-US/security/advisories/mfsa2022-26/#CVE-2022-34470

EPSS

Процентиль: 41%
0.00188
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 9.8
redhat
около 3 лет назад

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 9.8
nvd
больше 2 лет назад

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 9.8
github
больше 2 лет назад

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость функции nsSHistory почтового клиента Thunderbird, браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 41%
0.00188
Низкий