CVE-2022-28285: Medium severity firefox esr vulnerability
When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
Other sources
When generating the assembly code for MLoadTypedArrayElementHole, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-28285.
Which software is affected by this vulnerability?
This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
What is the severity level of CVE-2022-28285?
The severity level of CVE-2022-28285 is medium (6.5).
How can this vulnerability be exploited?
This vulnerability could have been used for an out of bounds memory read in conjunction with another vulnerability.
Where can I find more information about CVE-2022-28285?
You can find more information about CVE-2022-28285 on the Mozilla Bugzilla and Mozilla Security Advisories websites.