CVE-2022-22750

Scores

EPSS

0.000none0.0%
0%20%40%60%80%100%

Percentile: 0.0%

CVSS

6.5medium3.x
0246810

CVSS Score: 6.5/10

All CVSS Scores

CVSS 3.x
6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Description

By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.
This bug only affects Firefox for Windows and MacOS. Other operating systems are unaffected.. This vulnerability affects Firefox < 96.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdubuntu

Vulnerable Software (7)

Type: Configuration

Product: firefox

Operating System: ubuntu bionic 18.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu focal 20.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu hirsute 21.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu impish 21.10

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: ubuntu jammy 22.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Product: firefox

Operating System: debian

Trait:
{  "unaffected": true}

Source: debian

Type: Configuration

Vendor: mozilla

Product: firefox

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",          "versionEndExcluding": "96.0",          "vulnerable": true        ...

Source: nvd