Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.5
CVE-2022-34477

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin …

Fix: 102.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-34478

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser,…

Fix: 91.11 / 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-34474

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-34475

SVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via …

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-34470

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR…

Fix: 91.11 / 102.0+
Fix from $2,300 2022-12-22
Firefox HIGH 8.1
CVE-2022-34469

When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. …

Fix: 102.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-34471

When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If t…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-34473

The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however it incorrectly did not sanitiz…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31747

Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox …

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31748

Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in …

Fix: 101+
Fix from $2,300 2022-12-22
Firefox HIGH 8.8
CVE-2022-34468

An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefo…

Fix: 91.11 / 102.0+
Fix from $1,950 2022-12-22
Firefox Mobile MEDIUM 6.5
CVE-2022-31746

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Fi…

Fix: 102.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-31741

A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulne…

Fix: 91.10 / 101+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-31742

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid ke…

Fix: 91.10 / 101+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-31743

Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to es…

Fix: 101.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-31744

An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Securit…

Fix: 91.11 / 101.0+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31737

A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnera…

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox HIGH 8.8
CVE-2022-31739

When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influence…

Fix: 91.10 / 101+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-31740

On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable cras…

Fix: 91.10 / 101.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-31738

When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion …

Fix: 91.10 / 101+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31736

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91…

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox HIGH 8.8
CVE-2022-29918

Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99. Some of these bugs …

Fix: 100.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-2200EPSS 24%

If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privile…

Fix: 91.11 / 102.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-2505

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corr…

Fix: 102.1 / 103.0+
Fix from $1,950 2022-12-22
Thunderbird MEDIUM 6.5
CVE-2022-2226

An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital sig…

Fix: 91.11+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-29917

Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and F…

Fix: 91.9 / 100.0+
Fix from $2,300 2022-12-22
Thunderbird MEDIUM 6.5
CVE-2022-29913

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This v…

Fix: 91.9+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-29914

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attac…

Fix: 91.9 / 100.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-29916

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to pro…

Fix: 91.9 / 100.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.1
CVE-2022-29912

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefo…

Fix: 91.9 / 100.0+
Fix from $1,600 2022-12-22