CVE-2022-22754
- EPSS 0.03%
- Veröffentlicht 22.12.2022 20:15:17
- Zuletzt bearbeitet 16.04.2025 15:15:48
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird...
CVE-2022-22747
- EPSS 0.12%
- Veröffentlicht 22.12.2022 20:15:16
- Zuletzt bearbeitet 16.04.2025 16:15:22
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunde...
CVE-2022-22748
- EPSS 0.45%
- Veröffentlicht 22.12.2022 20:15:16
- Zuletzt bearbeitet 16.04.2025 15:15:47
Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-22749
- EPSS 0.31%
- Veröffentlicht 22.12.2022 20:15:16
- Zuletzt bearbeitet 16.04.2025 15:15:47
When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.
CVE-2022-22750
- EPSS 0.32%
- Veröffentlicht 22.12.2022 20:15:16
- Zuletzt bearbeitet 16.04.2025 16:15:22
By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only af...
CVE-2022-22743
- EPSS 0.43%
- Veröffentlicht 22.12.2022 20:15:15
- Zuletzt bearbeitet 16.04.2025 16:15:22
When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-22744
- EPSS 0.44%
- Veröffentlicht 22.12.2022 20:15:15
- Zuletzt bearbeitet 16.04.2025 16:15:22
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other o...
CVE-2022-22745
- EPSS 0.47%
- Veröffentlicht 22.12.2022 20:15:15
- Zuletzt bearbeitet 16.04.2025 15:15:47
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-22746
- EPSS 0.12%
- Veröffentlicht 22.12.2022 20:15:15
- Zuletzt bearbeitet 16.04.2025 15:15:47
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability ...
- EPSS 0.11%
- Veröffentlicht 22.12.2022 20:15:14
- Zuletzt bearbeitet 16.04.2025 16:15:21
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>*This bug only affec...