CVE-2022-38477 describes memory safety bugs in Firefox, Firefox ESR, and Thunderbird, specifically affecting versions prior to Firefox 104, Firefox ESR 102.2, and Thunderbird 102.2. These bugs, identified by Mozilla developers, could lead to memory corruption, potentially allowing for arbitrary code execution with sufficient effort. Rated with a CVSS score of 8.8 (High), this vulnerability is network-exploitable with low attack complexity, requiring user interaction, and could result in high impacts to confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and it is not listed in CISA's KEV catalog, its presence has been noted in community discussions and a SecurityWeek article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 104.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 102.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* | ||
< 102.2CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.