CVE-2022-22751 describes multiple memory safety bugs in Mozilla Firefox, Firefox ESR, and Thunderbird, specifically affecting versions prior to Firefox 96, Firefox ESR 91.5, and Thunderbird 91.5. These vulnerabilities carry a high CVSS score of 8.8, indicating a network-based attack requiring user interaction, with potential for high impact on confidentiality, integrity, and availability through arbitrary code execution. While the bugs showed evidence of memory corruption, there is no public exploit code available, nor is it listed in CISA's KEV catalog, suggesting it is not actively exploited in the wild. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 96.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 91.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 91.5CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.