Unrated severityNVD Advisory· Published Dec 22, 2022· Updated Apr 15, 2025
CVE-2022-46880
CVE-2022-46880
Description
A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105. This vulnerability affects Firefox ESR < 102.6, Firefox < 105, and Thunderbird < 102.6.
Affected products
42- osv-coords39 versionspkg:rpm/almalinux/firefoxpkg:rpm/almalinux/thunderbirdpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP4
< 102.6.0-1.el9_1.alma+ 38 more
- (no CPE)range: < 102.6.0-1.el9_1.alma
- (no CPE)range: < 102.6.0-2.el8_7.alma
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150200.8.96.1
- (no CPE)range: < 102.6.0-150200.8.96.1
- (no CPE)range: < 102.6.0-1.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150000.150.68.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-150200.152.70.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-112.142.1
- (no CPE)range: < 102.6.0-150200.8.96.1
- (no CPE)range: < 102.6.0-150200.8.96.1
- Range: unspecified
- Range: unspecified
- Mozilla/Firefox ESRv5Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- security.gentoo.org/glsa/202305-06mitrevendor-advisory
- security.gentoo.org/glsa/202305-13mitrevendor-advisory
- bugzilla.mozilla.org/show_bug.cgimitre
- www.mozilla.org/security/advisories/mfsa2022-40/mitre
- www.mozilla.org/security/advisories/mfsa2022-52/mitre
- www.mozilla.org/security/advisories/mfsa2022-53/mitre
News mentions
0No linked articles in our index yet.