CVE-2022-1802 is a critical vulnerability affecting Mozilla Firefox, Firefox ESR, Firefox for Android, and Thunderbird. It allows an attacker to achieve arbitrary code execution in a privileged context by corrupting Array object methods through prototype pollution. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over a network with user interaction, leading to high impacts on confidentiality, integrity, and availability. This zero-day vulnerability was actively exploited in the wild, including at Pwn2Own, and has garnered significant community and media attention, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 100.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 91.9.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 91.9.1CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* | ||
< 100.3.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.