CVE-2022-34479
- EPSS 0.15%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 19:16:04
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating s...
CVE-2022-34480
- EPSS 0.38%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.
CVE-2022-34481
- EPSS 0.24%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbir...
CVE-2022-34482
- EPSS 0.39%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...
CVE-2022-34483
- EPSS 0.52%
- Veröffentlicht 22.12.2022 20:15:33
- Zuletzt bearbeitet 15.04.2025 18:15:42
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...
CVE-2022-34474
- EPSS 0.24%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 20:15:37
Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affect...
CVE-2022-34475
- EPSS 0.53%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 20:15:37
SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript f...
CVE-2022-34476
- EPSS 0.59%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 19:16:03
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.
CVE-2022-34477
- EPSS 0.35%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 19:16:03
The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability aff...
CVE-2022-34478
- EPSS 0.16%
- Veröffentlicht 22.12.2022 20:15:32
- Zuletzt bearbeitet 15.04.2025 19:16:03
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wi...