Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2022-46873

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise prote…

Fix: 108.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-46874

A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This cou…

Fix: 102.6 / 108.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-46878

Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. …

Fix: 102.6 / 108.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-46875

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This…

Fix: 102.6 / 108.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-45421

Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence …

Fix: 102.5 / 107.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-46871

An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

Fix: 108.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.6
CVE-2022-46872

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br…

Fix: 102.6 / 108.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45419

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and…

Fix: 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45420

Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in poten…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox HIGH 7.8
CVE-2022-45415

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with …

Fix: 107.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45416

Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe …

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-45418

If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potentia…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-45412

When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string con…

Fix: 102.5 / 107.0+
Fix from $1,950 2022-12-22
Thunderbird HIGH 8.1
CVE-2022-45414

If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER att…

Fix: 102.5.1+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45410

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-45411

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and …

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-45413

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be…

Fix: 107.0+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-45406

If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a Base…

Fix: 102.5 / 107.0+
Fix from $2,300 2022-12-22
Firefox HIGH 8.8
CVE-2022-45409

The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, lead…

Fix: 102.5 / 107.0+
Fix from $1,950 2022-12-22
Firefox HIGH 7.5
CVE-2022-45407

If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exp…

Fix: 107.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45408

Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, re…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-42932

Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these b…

Fix: 102.4 / 106.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45403

Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined w…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45404

Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notifica…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-45405

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable cr…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-42928

Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption an…

Fix: 102.4 / 106.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.1
CVE-2022-42927

A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntrie…

Fix: 102.4 / 106.0+
Fix from $1,950 2022-12-22
Firefox HIGH 7.1
CVE-2022-42930

If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerabi…

Fix: 106.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-42929

If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart…

Fix: 102.4 / 106.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-40962

Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present …

Fix: 102.3 / 105.0+
Fix from $1,950 2022-12-22