Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-40958 By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite c… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-40959 During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into un… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-40960 Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-40961 During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This iss… Firefox 105.0+ Fix from $1,6002022-12-22 HIGH 7.8 CVE-2022-3155 When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received fil… Thunderbird 102.3+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-40957 Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Fire… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-40956 When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vuln… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 MEDIUM 5.5 CVE-2022-3266 An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 1… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-38477 Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these b… Firefox 102.2 / 104.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-38478 Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs sho… Firefox 91.13 / 102.2+ Fix from $1,9502022-12-22 HIGH 8.1 CVE-2022-3033 If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv=… Thunderbird 91.13.1 / 102.2.1+ Fix from $1,9502022-12-22 HIGH 7.5 CVE-2022-38476 A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock prot… Firefox Esr 102.2+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-3032 When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML docum… Thunderbird 91.13.1 / 102.2.1+ Fix from $1,6002022-12-22 CRITICAL 9.8 CVE-2022-36320 Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corr… Firefox 103.0+ Fix from $2,3002022-12-22 HIGH 8.8 CVE-2022-38473 A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerab… Firefox 91.13 / 102.2+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-38472 An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar… Firefox 91.13 / 102.2+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-38475 An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not … Firefox 104.0+ Fix from $1,6002022-12-22 HIGH 7.5 CVE-2022-36319 When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerabili… Firefox 91.12 / 102.1+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-36317 When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denia… Firefox 103.0+ Fix from $1,6002022-12-22 MEDIUM 6.1 CVE-2022-36316 When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha… Firefox 103.0+ Fix from $1,6002022-12-22 MEDIUM 5.3 CVE-2022-36318 When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1,… Firefox 91.12 / 102.1+ Fix from $1,6002022-12-22 CRITICAL 9.8 CVE-2022-34485 Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs sh… Firefox Mitigation only Fix from $2,3002022-12-22 HIGH 8.8 CVE-2022-34484 The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and… Firefox 91.11 / 102.0+ Fix from $1,9502022-12-22 MEDIUM 5.5 CVE-2022-36314 When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from… Firefox 102.1 / 103.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-34480 Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite… Firefox 102.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-34481 In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was t… Firefox 91.11 / 102.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-34482 An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe… Firefox 102.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-34483 An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe… Firefox 102.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-34479 A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential us… Firefox 91.11 / 102.0+ Fix from $1,6002022-12-22 CRITICAL 9.8 CVE-2022-34476 ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability af… Firefox 102.0+ Fix from $2,3002022-12-22