CVE-2022-3266
Published on: Not Yet Published
Last Modified on: 12/30/2022 10:14:00 PM UTC
Certain versions of Firefox from Mozilla contain the following vulnerability:
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
- CVE-2022-3266 has been assigned by
secur[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Mozilla - Firefox ESR version < 102.3
- Affected Vendor/Software:
Mozilla - Thunderbird version < 102.3
- Affected Vendor/Software:
Mozilla - Firefox version < 105
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Security Vulnerabilities fixed in Thunderbird 102.3 — Mozilla | www.mozilla.org text/html |
![]() |
Security Vulnerabilities fixed in Firefox ESR 102.3 — Mozilla | www.mozilla.org text/html |
![]() |
Security Vulnerabilities fixed in Firefox 105 — Mozilla | www.mozilla.org text/html |
![]() |
Access Denied | bugzilla.mozilla.org text/html |
![]() |
Related QID Numbers
- 182179 Debian Security Update for firefox-esrthunderbird (CVE-2022-3266)
- 198968 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5649-1)
- 199024 Ubuntu Security Notification for Thunderbird Vulnerabilities (USN-5724-1)
- 354760 Amazon Linux Security Advisory for thunderbird : ALAS2-2023-1951
- 753237 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2022:3800-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Mozilla | Firefox | All | All | All | All |
Application | Mozilla | Firefox Esr | All | All | All | All |
Application | Mozilla | Thunderbird | All | All | All | All |
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*:
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*:
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Hey @MozillaSecurity are you going to around to publishing CVE-2022-3266 soon? It has been 8 days since your adviso… twitter.com/i/web/status/1… | 2022-09-28 16:58:34 |