CVE-2022-31737 An attacker wrote code outside of WebGL memory, which could lead to memory corruption and a crash.
A malicious website could cause a user to inadvertently click a malicous link, leading to code execution. This vulnerability affects Thunderbird 91.10, Firefox 101,
CVE-2022-38476 Data races in the code>PK11_ChangePW/code> function could lead to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password.
It has been assigned the CVE identifier CVE-2017-5208, and a full description of the vulnerability can be found here. Workarounds There are no
CVE-2022-31748 Gabriele Svelto, Timothy Nikkel, Randell Jesup, and the Mozilla Fuzzing Team found memory safety bugs in Firefox 100.
It is likely that some of these issues were discovered by automated tools. For example, it is possible to use the Google fuzzing framework to
CVE-2022-34485 Mozilla developers found vulnerabilities in Firefox 101.
It is highly recommended to upgrade your installations to latest stable version as soon as possible. For Debian/Ubuntu users there are repositories with latest
CVE-2022-45412 A symlink can produce an error message with a memory buffer when it is resolved to a string.
It is caused by a bug in the implementation of the ''enumerateSymbolicNameEntries'' method that is used by the ''FileSystemEnumerator&
Episode
00:00:00
00:00:00