CVE-2022-34468
- EPSS 0.52%
- Veröffentlicht 22.12.2022 20:15:30
- Zuletzt bearbeitet 15.04.2025 19:16:02
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
CVE-2022-31741
- EPSS 0.27%
- Veröffentlicht 22.12.2022 20:15:29
- Zuletzt bearbeitet 15.04.2025 19:15:58
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
CVE-2022-31742
- EPSS 0.36%
- Veröffentlicht 22.12.2022 20:15:29
- Zuletzt bearbeitet 15.04.2025 19:15:58
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violat...
CVE-2022-31743
- EPSS 0.62%
- Veröffentlicht 22.12.2022 20:15:29
- Zuletzt bearbeitet 15.04.2025 19:15:58
Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox...
CVE-2022-31744
- EPSS 0.07%
- Veröffentlicht 22.12.2022 20:15:29
- Zuletzt bearbeitet 15.04.2025 19:15:59
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and...
CVE-2022-31745
- EPSS 0.34%
- Veröffentlicht 22.12.2022 20:15:29
- Zuletzt bearbeitet 15.04.2025 19:15:59
If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101.
CVE-2022-31737
- EPSS 0.39%
- Veröffentlicht 22.12.2022 20:15:28
- Zuletzt bearbeitet 16.04.2025 14:15:21
A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
CVE-2022-31738
- EPSS 0.16%
- Veröffentlicht 22.12.2022 20:15:28
- Zuletzt bearbeitet 16.04.2025 14:15:21
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR <...
CVE-2022-31739
- EPSS 0.48%
- Veröffentlicht 22.12.2022 20:15:28
- Zuletzt bearbeitet 16.04.2025 14:15:21
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Wi...
CVE-2022-31740
- EPSS 0.24%
- Veröffentlicht 22.12.2022 20:15:28
- Zuletzt bearbeitet 16.04.2025 14:15:22
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.