a use-after-free couldhave been triggered by destroying an object during JavaScript execution andthen referencing the object through a freed pointer, leading to a potentialexploitable crash. This ...">CVE-2022-28282 - vulnerability database | Vulners.com a use-after-free couldhave been triggered by destroying an object during JavaScript execution andthen referencing the object through a freed pointer, leading to a potentialexploitable crash. This ..."> a use-after-free couldhave been triggered by destroying an object during JavaScript execution andthen referencing the object through a freed pointer, leading to a potentialexploitable crash. This ..."> a use-after-free couldhave been triggered by destroying an object during JavaScript execution andthen referencing the object through a freed pointer, leading to a potentialexploitable crash. This ...">
Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-28282
HistoryApr 06, 2022 - 12:00 a.m.

CVE-2022-28282

2022-04-0600:00:00
ubuntu.com
ubuntu.com
15
use-after-free
link
localization
javascript
exploitable
thunderbird
firefox esr

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

55.3%

By using a link with <code>rel=“localization”</code> a use-after-free could
have been triggered by destroying an object during JavaScript execution and
then referencing the object through a freed pointer, leading to a potential
exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox <
99, and Firefox ESR < 91.8.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchfirefox< 99.0+build2-0ubuntu0.18.04.2UNKNOWN
ubuntu20.04noarchfirefox< 99.0+build2-0ubuntu0.20.04.2UNKNOWN
ubuntu21.10noarchfirefox< 99.0+build2-0ubuntu0.21.10.2UNKNOWN
ubuntu22.04noarchfirefox< 1:1snap1-0ubuntu1UNKNOWN
ubuntu22.10noarchfirefox< 1:1snap1-0ubuntu1UNKNOWN
ubuntu23.04noarchfirefox< 1:1snap1-0ubuntu1UNKNOWN
ubuntu18.04noarchthunderbird< 1:91.8.1+build1-0ubuntu0.18.04.1UNKNOWN
ubuntu20.04noarchthunderbird< 1:91.8.1+build1-0ubuntu0.20.04.1UNKNOWN
ubuntu21.10noarchthunderbird< 1:91.8.1+build1-0ubuntu0.21.10.1UNKNOWN

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

55.3%