<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbirdUpgrade firefox | May 4, 2022 | Apr 11, 2022 |
| Alpine Linux | — | Upgrade nssUpgrade librewolfUpgrade firefox-esrUpgrade thunderbirdUpgrade firefox | Mar 26, 2024 | Dec 22, 2022 |
| Amazon Linux Ami 2 | — | Upgrade thunderbirdUpgrade thunderbird-debuginfo | Jul 4, 2022 | Jul 4, 2022 |
| Centos_linux | — | Upgrade thunderbirdUpgrade firefoxUpgrade thunderbird-debugsourceUpgrade firefox-debugsourceUpgrade firefox-debuginfoUpgrade thunderbird-debuginfo | Apr 11, 2022 | Apr 8, 2022 |
| Debian | — | Upgrade thunderbirdUpgrade firefox-esr | Apr 8, 2022 | Apr 8, 2022 |
| Gentoo Linux | — | Upgrade dev-libs/nss. | Dec 19, 2022 | Dec 19, 2022 |
| Mfsa2022 13 | — | Upgrade to Mozilla Firefox version 99.0 | Apr 6, 2022 | Apr 5, 2022 |
| Mfsa2022 14 | — | Upgrade to Mozilla Firefox ESR version 91.8 | Apr 6, 2022 | Apr 5, 2022 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 91.8 | Apr 7, 2022 | Apr 5, 2022 |
| Oracle_linux | — | oracle-linux-upgrade-firefoxoracle-linux-upgrade-thunderbird | Apr 9, 2022 | Apr 5, 2022 |
| Redhat_linux | — | Upgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoNo solution existsUpgrade firefox-debuginfoUpgrade firefoxUpgrade thunderbird | Apr 11, 2022 | Apr 8, 2022 |
| Rocky_linux | rocky-upgrade-firefoxrocky-upgrade-firefox-debuginforocky-upgrade-firefox-debugsourcerocky-upgrade-thunderbirdrocky-upgrade-thunderbird-debuginforocky-upgrade-thunderbird-debugsource | Mar 5, 2024 | Dec 22, 2022 | |
| Suse | — | suse-upgrade-libfreebl3suse-upgrade-libfreebl3-32bitsuse-upgrade-libfreebl3-hmacsuse-upgrade-libfreebl3-hmac-32bitsuse-upgrade-libsoftokn3suse-upgrade-libsoftokn3-32bitsuse-upgrade-libsoftokn3-hmacsuse-upgrade-libsoftokn3-hmac-32bitsuse-upgrade-mozilla-nsssuse-upgrade-mozilla-nss-32bitsuse-upgrade-mozilla-nss-certssuse-upgrade-mozilla-nss-certs-32bitsuse-upgrade-mozilla-nss-develsuse-upgrade-mozilla-nss-sysinitsuse-upgrade-mozilla-nss-sysinit-32bitsuse-upgrade-mozilla-nss-toolssuse-upgrade-mozillafirefoxsuse-upgrade-mozillafirefox-branding-upstreamsuse-upgrade-mozillafirefox-develsuse-upgrade-mozillafirefox-translations-commonsuse-upgrade-mozillafirefox-translations-othersuse-upgrade-mozillathunderbirdsuse-upgrade-mozillathunderbird-translations-commonsuse-upgrade-mozillathunderbird-translations-other | Oct 26, 2022 | Apr 13, 2022 |
| Ubuntu | ubuntu-upgrade-firefoxubuntu-upgrade-thunderbird | Apr 8, 2022 | Apr 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub