CVE-2022-28281
HIGH EXPLOITEDMozilla Firefox < 99.0 - Out-of-Bounds Write
Title source: ruleDescription
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
Exploits (1)
References (4)
Scores
CVSS v3
8.8
EPSS
0.1457
EPSS Percentile
94.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2022-08-15
CWE
CWE-787
Status
published
Products (3)
mozilla/firefox
< 99.0
mozilla/firefox_esr
< 91.8
mozilla/thunderbird
< 91.8
Published
Dec 22, 2022
Tracked Since
Feb 18, 2026