CVE-2022-46881
HIGHFirefox < 106.0, Firefox ESR < 102.6, Thunderbird < 102.6 - Out-of-bounds Write in WebGL
Title source: llmDescription
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR < 102.6, and Thunderbird < 102.6.
References (6)
Core 6
Core References
Issue Tracking, Permissions Required
https://bugzilla.mozilla.org/show_bug.cgi?id=1770930
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-44/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-52/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2022-53/
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202305-06
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202305-13
Scores
CVSS v3
8.8
EPSS
0.0025
EPSS Percentile
48.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (3)
mozilla/firefox
< 106.0
mozilla/firefox_esr
< 102.6
mozilla/thunderbird
< 102.6
Published
Dec 22, 2022
Tracked Since
Feb 18, 2026