PT-2022-4673 · Mozilla+5 · Firefox+5

Christian Holler

·

Published

2022-08-23

·

Updated

2025-03-14

·

CVE-2022-38475

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 104
Description The issue is related to insufficient input validation when handling array element values, allowing a remote attacker to bypass security restrictions. An attacker could write a value to the first element in a zero-length JavaScript array without writing to an invalid memory address.
Recommendations For versions prior to 104, update to version 104 or later to resolve the issue. As a temporary workaround, consider restricting the use of zero-length JavaScript arrays until a patch is available.

Exploit

Fix

Incorrect Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2481
ALT-PU-2022-2930
ALT-PU-2023-1139
ALT-PU-2023-4339
ALT-PU-2023-5754
ALT-PU-2023-6436
ALT-PU-2024-3614
BDU:2022-05560
CVE-2022-38475
OESA-2025-1265
OESA-2025-1268
OPENSUSE-SU-2024:12286-1
OPENSUSE-SU-2024:14572-1
USN-5581-1

Affected Products

Alt Linux
Astra Linux
Firefox
Linuxmint
Red Os
Ubuntu