Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-22756


If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.


Published

2022-12-22T20:15:18.467

Last Modified

2025-04-16T15:15:48.823

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox < 97.0 Yes
Application mozilla firefox_esr < 91.6 Yes
Application mozilla thunderbird < 91.6 Yes

References