CVE-2022-45403
- EPSS 0.16%
- Veröffentlicht 22.12.2022 20:15:41
- Zuletzt bearbeitet 15.04.2025 16:15:20
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This ...
CVE-2022-45404
- EPSS 0.15%
- Veröffentlicht 22.12.2022 20:15:41
- Zuletzt bearbeitet 15.04.2025 16:15:20
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Fi...
CVE-2022-45405
- EPSS 0.15%
- Veröffentlicht 22.12.2022 20:15:41
- Zuletzt bearbeitet 15.04.2025 16:15:21
Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
CVE-2022-42927
- EPSS 0.14%
- Veröffentlicht 22.12.2022 20:15:40
- Zuletzt bearbeitet 15.04.2025 16:15:19
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
CVE-2022-42928
- EPSS 0.19%
- Veröffentlicht 22.12.2022 20:15:40
- Zuletzt bearbeitet 15.04.2025 16:15:19
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and...
CVE-2022-42929
- EPSS 0.2%
- Veröffentlicht 22.12.2022 20:15:40
- Zuletzt bearbeitet 15.04.2025 16:15:19
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ...
CVE-2022-42930
- EPSS 0.28%
- Veröffentlicht 22.12.2022 20:15:40
- Zuletzt bearbeitet 15.04.2025 16:15:20
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.
CVE-2022-40958
- EPSS 0.37%
- Veröffentlicht 22.12.2022 20:15:39
- Zuletzt bearbeitet 15.04.2025 15:15:59
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affec...
CVE-2022-40959
- EPSS 0.13%
- Veröffentlicht 22.12.2022 20:15:39
- Zuletzt bearbeitet 15.04.2025 15:15:59
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefo...
CVE-2022-40960
- EPSS 0.16%
- Veröffentlicht 22.12.2022 20:15:39
- Zuletzt bearbeitet 15.04.2025 15:15:59
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.