CVE-2022-46880: Use After Free
Published Sep 20, 2022
·Updated
A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.
Affected Software
6 affected componentsFixes available
Mozilla Thunderbird<102.6
102.6
Mozilla Firefox<105.0
Mozilla Firefox ESR<102.6
Mozilla Thunderbird<102.6
Mozilla Firefox<105
105
Mozilla Firefox ESR<102.6
102.6
Event History
Sep 20, 2022
CVE Published
via Mozilla·12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-46880?
The severity of CVE-2022-46880 is high with a CVSS score of 6.5.
2
Which products are affected by CVE-2022-46880?
CVE-2022-46880 affects Mozilla Thunderbird, Mozilla Firefox, and Mozilla Firefox ESR.
3
What is the potential impact of CVE-2022-46880?
CVE-2022-46880 could lead to a use-after-free vulnerability, potentially causing a crash and exploitation.
4
What is the remedy for CVE-2022-46880?
The remedy for CVE-2022-46880 is to update to the fixed versions of Mozilla Thunderbird 102.6, Mozilla Firefox 105, or Mozilla Firefox ESR 102.6.
5
Where can I find more information about CVE-2022-46880?
You can find more information about CVE-2022-46880 in the Mozilla Security Advisory MFSA2022-53 and MFSA2022-40.