Loading HuntDB...

GHSA-vfrp-p8qm-9m8x

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

Related CVEs

Key Information

GHSA ID
GHSA-vfrp-p8qm-9m8x
Published
May 14, 2022 1:52 AM
Last Modified
May 14, 2022 1:52 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 14, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.