CVE-2022-42928: Null Pointer Dereference
Published Oct 18, 2022
·Updated
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash.
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<102.4
102.4
Mozilla Firefox<106.0
Mozilla Firefox ESR<102.4
Mozilla Thunderbird<102.4
Mozilla Firefox<106
106
Mozilla Firefox ESR<102.4
102.4
Event History
Oct 18, 2022
CVE Published
via Mozilla·12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-42928.
2
How does this vulnerability affect Mozilla Firefox?
This vulnerability affects Mozilla Firefox versions up to and exclusive of 106.
3
Which versions of Firefox ESR are affected by this vulnerability?
This vulnerability affects Firefox ESR versions up to and exclusive of 102.4.
4
What is the severity of CVE-2022-42928?
The severity of CVE-2022-42928 is rated as high with a CVSS score of 8.8.
5
How can I fix this vulnerability in Thunderbird?
To fix this vulnerability in Thunderbird, update to version 102.4 or later.