Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-46873 Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise prote… Firefox 108.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-46874 A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This cou… Firefox 102.6 / 108.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-46878 Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. … Firefox 102.6 / 108.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-46875 The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This… Firefox 102.6 / 108.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-45421 Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence … Firefox 102.5 / 107.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-46871 An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108. Firefox 108.0+ Fix from $1,9502022-12-22 HIGH 8.6 CVE-2022-46872 An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br… Firefox 102.6 / 108.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-45419 If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and… Firefox 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-45420 Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in poten… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 HIGH 7.8 CVE-2022-45415 When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with … Firefox 107.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-45416 Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe … Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-45418 If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potentia… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-45412 When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string con… Firefox 102.5 / 107.0+ Fix from $1,9502022-12-22 HIGH 8.1 CVE-2022-45414 If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER att… Thunderbird 102.5.1+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-45410 When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-45411 Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and … Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-45413 Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be… Firefox 107.0+ Fix from $1,6002022-12-22 CRITICAL 9.8 CVE-2022-45406 If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a Base… Firefox 102.5 / 107.0+ Fix from $2,3002022-12-22 HIGH 8.8 CVE-2022-45409 The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, lead… Firefox 102.5 / 107.0+ Fix from $1,9502022-12-22 HIGH 7.5 CVE-2022-45407 If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exp… Firefox 107.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-45408 Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, re… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-42932 Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these b… Firefox 102.4 / 106.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-45403 Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined w… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-45404 Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notifica… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-45405 Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable cr… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-42928 Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption an… Firefox 102.4 / 106.0+ Fix from $1,9502022-12-22 HIGH 8.1 CVE-2022-42927 A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntrie… Firefox 102.4 / 106.0+ Fix from $1,9502022-12-22 HIGH 7.1 CVE-2022-42930 If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerabi… Firefox 106.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-42929 If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart… Firefox 102.4 / 106.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-40962 Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present … Firefox 102.3 / 105.0+ Fix from $1,9502022-12-22