CVE-2022-22744
- EPSS 0.44%
- Veröffentlicht 22.12.2022 20:15:15
- Zuletzt bearbeitet 16.04.2025 16:15:22
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other o...
CVE-2022-22745
- EPSS 0.15%
- Veröffentlicht 22.12.2022 20:15:15
- Zuletzt bearbeitet 16.04.2025 15:15:47
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-22746
- EPSS 0.03%
- Veröffentlicht 22.12.2022 20:15:15
- Zuletzt bearbeitet 16.04.2025 15:15:47
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability ...
CVE-2022-22737
- EPSS 0.11%
- Veröffentlicht 22.12.2022 20:15:14
- Zuletzt bearbeitet 16.04.2025 15:15:47
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, ...
CVE-2022-22738
- EPSS 0.15%
- Veröffentlicht 22.12.2022 20:15:14
- Zuletzt bearbeitet 16.04.2025 15:15:47
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-22739
- EPSS 0.1%
- Veröffentlicht 22.12.2022 20:15:14
- Zuletzt bearbeitet 16.04.2025 16:15:21
Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-22740
- EPSS 0.15%
- Veröffentlicht 22.12.2022 20:15:14
- Zuletzt bearbeitet 16.04.2025 16:15:21
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbi...
CVE-2022-22741
- EPSS 0.12%
- Veröffentlicht 22.12.2022 20:15:14
- Zuletzt bearbeitet 16.04.2025 16:15:21
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-22742
- EPSS 0.1%
- Veröffentlicht 22.12.2022 20:15:14
- Zuletzt bearbeitet 16.04.2025 16:15:22
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2022-1529
- EPSS 3.71%
- Veröffentlicht 22.12.2022 20:15:13
- Zuletzt bearbeitet 16.04.2025 16:15:20
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process...