CVE-2022-3266: Medium severity thunderbird vulnerability
Published Sep 20, 2022
·Updated
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash.
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<102.3
102.3
Mozilla Firefox<105.0
Mozilla Firefox ESR<102.3
Mozilla Thunderbird<102.3
Mozilla Firefox<105
105
Mozilla Firefox ESR<102.3
102.3
Event History
Sep 20, 2022
CVE Published
12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2022-3266.
2
What is the severity of CVE-2022-3266?
The severity of CVE-2022-3266 is high with a severity value of 7.
3
Which software is affected by CVE-2022-3266?
CVE-2022-3266 affects Mozilla Thunderbird up to version 102.3, Mozilla Firefox up to version 105, and Mozilla Firefox ESR up to version 102.3.
4
What is the impact of CVE-2022-3266?
CVE-2022-3266 can result in a potentially exploitable crash due to an out-of-bounds read when decoding H264 video.
5
How can I fix CVE-2022-3266?
To fix CVE-2022-3266, update Mozilla Thunderbird to version 102.3 or later, Mozilla Firefox to version 105 or later, or Mozilla Firefox ESR to version 102.3 or later.