CVE-2022-36314
- EPSS 0.03%
- Veröffentlicht 22.12.2022 20:15:34
- Zuletzt bearbeitet 15.04.2025 18:15:43
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaf...
CVE-2022-34479
- EPSS 0.1%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 19:16:04
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating s...
CVE-2022-34480
- EPSS 0.31%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.
CVE-2022-34481
- EPSS 0.13%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbir...
CVE-2022-34482
- EPSS 0.28%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...
CVE-2022-34483
- EPSS 0.3%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...
CVE-2022-34474
- EPSS 0.19%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 20:15:37
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affect...
CVE-2022-34475
- EPSS 0.86%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 20:15:37
SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript f...
CVE-2022-34476
- EPSS 0.59%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 19:16:03
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.
CVE-2022-34477
- EPSS 0.36%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 19:16:03
The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability aff...