CVE-2022-22751: High severity thunderbird vulnerability
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memory safety bugs present in Firefox 95 and Firefox ESR 91.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-22751?
CVE-2022-22751 has been classified as a high severity vulnerability due to its potential for memory corruption.
How do I fix CVE-2022-22751?
To fix CVE-2022-22751, users should update to Firefox version 96, Firefox ESR version 91.5, or Thunderbird version 91.5.
What versions of Firefox are affected by CVE-2022-22751?
CVE-2022-22751 affects Firefox versions up to 95 and Firefox ESR versions up to 91.4.
Can CVE-2022-22751 lead to remote code execution?
Yes, CVE-2022-22751 may potentially result in remote code execution due to memory safety issues.
Who reported CVE-2022-22751?
CVE-2022-22751 was reported by Mozilla developers including Calixte Denizet, Kershaw Chang, and others.