CVE-2022-34484: Use After Free
The Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101 and Firefox ESR 91.10. Some of these bugs showed evidence of JavaScript prototype or memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Other sources
The Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101 and Firefox ESR 91.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-34484?
The severity of CVE-2022-34484 is high.
How can CVE-2022-34484 be exploited?
CVE-2022-34484 can be exploited to run arbitrary code.
Which versions of Firefox and Firefox ESR are affected by CVE-2022-34484?
Versions 101 and 91.10 of Firefox and Firefox ESR are affected by CVE-2022-34484.
What is the recommended remedy for CVE-2022-34484?
The recommended remedy for CVE-2022-34484 is to update to version 91.11 for Firefox ESR and Thunderbird, and version 102 for Thunderbird and Firefox.
Where can I find more information about CVE-2022-34484?
You can find more information about CVE-2022-34484 in the following references: [Bugzilla - Bug 1763634](https://bugzilla.mozilla.org/buglist.cgi?bug_id=1763634%2C1772651), [Mozilla Security Advisories - MFSA2022-26](https://www.mozilla.org/en-US/security/advisories/mfsa2022-26/), [Mozilla Security Advisories - MFSA2022-24](https://www.mozilla.org/en-US/security/advisories/mfsa2022-24/)