CVE-2022-34485
Published on: Not Yet Published
Last Modified on: 12/30/2022 06:14:00 PM UTC
Certain versions of Firefox from Mozilla contain the following vulnerability:
Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102.
- CVE-2022-34485 has been assigned by
secur[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Mozilla - Firefox version < 102
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Bug List | bugzilla.mozilla.org text/html |
![]() |
Security Vulnerabilities fixed in Firefox 102 — Mozilla | www.mozilla.org text/html |
![]() |
Related QID Numbers
- 198849 Ubuntu Security Notification for Firefox Vulnerabilities (USN-5504-1)
- 376705 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-24)
- 502853 Alpine Linux Security Update for firefox
- 710582 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 202208-08)
- 752583 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3273-1)
- 752590 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3272-1)
- 752611 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3396-1)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Mozilla | Firefox | 101.0 | All | All | All |
Application | Mozilla | Firefox | 101.0.1 | All | All | All |
- cpe:2.3:a:mozilla:firefox:101.0:*:*:*:*:*:*:*:
- cpe:2.3:a:mozilla:firefox:101.0.1:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Mozilla Firefox code execution | CVE-2022-34485 - redpacketsecurity.com/mozilla-firefo… #CVE #Vulnerability #OSINT #ThreatIntel #Cyber | 2022-06-29 09:02:15 |
![]() |
CVE-2022-34485 | 2022-12-22 20:38:40 |