8.8 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
0.002 Low
EPSS
Percentile
51.5%
Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and
the Mozilla Fuzzing Team reported memory safety bugs present in Firefox
106. Some of these bugs showed evidence of memory corruption and we presume
that with enough effort some of these could have been exploited to run
arbitrary code.<br />Note: This advisory was added on December 13th, 2022
after discovering it was inadvertently left out of the original advisory.
The fix was included in the original release of Firefox 107. This
vulnerability affects Firefox < 107.
Author | Note |
---|---|
tyhicks | mozjs contains a copy of the SpiderMonkey JavaScript engine |
mdeslaur | starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap |