CVE-2022-46880

A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105. This vulnerability affects Firefox ESR < 102.6, Firefox < 105, and Thunderbird < 102.6.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

15 Apr 2025, 14:15

Type Values Removed Values Added
References (GENTOO) https://security.gentoo.org/glsa/202305-13 - () https://security.gentoo.org/glsa/202305-13 -
References (MISC) https://www.mozilla.org/security/advisories/mfsa2022-40/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-40/ - Vendor Advisory
References (GENTOO) https://security.gentoo.org/glsa/202305-06 - () https://security.gentoo.org/glsa/202305-06 -
References (MISC) https://www.mozilla.org/security/advisories/mfsa2022-52/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-52/ - Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2022-53/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2022-53/ - Vendor Advisory
References (MISC) https://bugzilla.mozilla.org/show_bug.cgi?id=1749292 - Issue Tracking, Permissions Required () https://bugzilla.mozilla.org/show_bug.cgi?id=1749292 - Issue Tracking, Permissions Required

03 May 2023, 12:16

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202305-13 -

03 May 2023, 11:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202305-06 -

Information

Published : 2022-12-22 20:15

Updated : 2025-04-15 14:15


NVD link : CVE-2022-46880

Mitre link : CVE-2022-46880


JSON object : View

Products Affected

mozilla

  • thunderbird
  • firefox
  • firefox_esr
CWE
CWE-416

Use After Free