PT-2022-2161 · Mozilla+4 · Firefox+4

Randell Jesup

+1

·

Published

2022-04-05

·

Updated

2024-12-12

·

CVE-2022-28288

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 99
Description The issue is related to a buffer overflow in memory, which could allow a remote attacker to execute arbitrary code using a specially crafted web page. Memory safety bugs were reported, showing evidence of memory corruption, and it is presumed that some of these could be exploited to run arbitrary code.
Recommendations For versions prior to 99, update to version 99 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable web pages until the update is applied.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1642
ALT-PU-2022-2458
ALT-PU-2022-2929
ALT-PU-2022-2930
ALT-PU-2023-1138
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-02132
CVE-2022-28288
OPENSUSE-SU-2024:11975-1
OPENSUSE-SU-2024:14572-1
USN-5370-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Ubuntu