CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2022-34477

    Last Modified: 15 Apr 2025

    The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-34482

    Last Modified: 15 Apr 2025

    An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34483. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-34483

    Last Modified: 15 Apr 2025

    An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34482. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-34485

    Last Modified: 15 Apr 2025

    Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-36317

    Last Modified: 15 Apr 2025

    When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 103.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-47942

    Last Modified: 15 Apr 2025

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2021-4126

    Last Modified: 16 Apr 2025

    When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list gateway, Thunderbird only considered the inner signed message for the signature validity. This gave the false impression that the additional contents were also covered by the digital signature. Starting with Thunderbird version 91.4.1, only the signature that belongs to the top level MIME part will be considered for the displayed status. This vulnerability affects Thunderbird < 91.4.1.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2021-4128

    Last Modified: 16 Apr 2025

    When transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentially exploitable crash.<br>*This bug only affects Firefox on MacOS. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2021-4221

    Last Modified: 16 Apr 2025

    If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*<br>*Note*: Due to a clerical error this advisory was not included in the original announcement, and was added in Feburary 2022. This vulnerability affects Firefox < 92.

    Published: 22 Dec 2022
    7.8
    High

    CVE-2022-0517

    Last Modified: 16 Apr 2025

    Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to launch arbitrary code with SYSTEM privilege. This vulnerability affects Mozilla VPN < 2.7.1.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-0843

    Last Modified: 16 Apr 2025

    Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98.

    Published: 22 Dec 2022
    6.3
    Medium

    CVE-2020-36624

    Last Modified: 21 Nov 2024

    A vulnerability was found in ahorner text-helpers up to 1.0.x. It has been declared as critical. This vulnerability affects unknown code of the file lib/text_helpers/translation.rb. The manipulation of the argument link leads to use of web link to untrusted target with window.opener access. The attack can be initiated remotely. Upgrading to version 1.1.0 is able to address this issue. The name of the patch is 184b60ded0e43c985788582aca2d1e746f9405a3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216520.

    Published: 22 Dec 2022
    7
    High

    CVE-2022-22736

    Last Modified: 16 Apr 2025

    If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries. However the install directory is not world-writable by default.<br>*This bug only affects Firefox for Windows in a non-default installation. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-22762

    Last Modified: 16 Apr 2025

    Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-22749

    Last Modified: 16 Apr 2025

    When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-22750

    Last Modified: 16 Apr 2025

    By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only affects Firefox for Windows and MacOS. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-22757

    Last Modified: 16 Apr 2025

    Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-22758

    Last Modified: 16 Apr 2025

    When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-31743

    Last Modified: 15 Apr 2025

    Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.

    Published: 22 Dec 2022
    5
    Medium

    CVE-2022-23541

    Last Modified: 13 Feb 2025

    jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured so that passing a poorly implemented key retrieval function referring to the `secretOrPublicKey` argument from the readme link will result in incorrect verification of tokens. There is a possibility of using a different algorithm and key combination in verification, other than the one that was used to sign the tokens. Specifically, tokens signed with an asymmetric public key could be verified with a symmetric HS256 algorithm. This can lead to successful validation of forged tokens. If your application is supporting usage of both symmetric key and asymmetric key in jwt.verify() implementation with the same key retrieval function. This issue has been patched, please update to version 9.0.0.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-45966

    Last Modified: 15 Apr 2025

    here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-46101

    Last Modified: 15 Apr 2025

    AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-46102

    Last Modified: 15 Apr 2025

    AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-4646

    Last Modified: 9 Apr 2025

    Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-4647

    Last Modified: 9 Apr 2025

    Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-46873

    Last Modified: 15 Apr 2025

    Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-46879

    Last Modified: 15 Apr 2025

    Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 107. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-46885

    Last Modified: 15 Apr 2025

    Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-47926

    Last Modified: 15 Apr 2025

    AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-47928

    Last Modified: 21 Nov 2024

    In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.

    Published: 22 Dec 2022
    9.1
    Critical

    CVE-2022-47931

    Last Modified: 15 Apr 2025

    IO FinNet tss-lib before 2.0.0 allows a collision of hash values.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-47938

    Last Modified: 15 Apr 2025

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-bounds read and OOPS for SMB2_TREE_CONNECT.

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-47943

    Last Modified: 15 Apr 2025

    An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.

    Published: 22 Dec 2022
    5.5
    Medium

    CVE-2022-47946

    Last Modified: 15 Apr 2025

    An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situations by forking a process and then quickly terminating it. NOTE: later kernel versions, such as the 5.15 longterm series, substantially changed the implementation of io_sqpoll_wait_sq.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-28288

    Last Modified: 16 Apr 2025

    Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 98. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 99.

    Published: 22 Dec 2022
    5.9
    Medium

    CVE-2022-40897

    Last Modified: 4 Nov 2025

    Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

    Published: 22 Dec 2022
    8.1
    High

    CVE-2022-34469

    Last Modified: 15 Apr 2025

    When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-34471

    Last Modified: 15 Apr 2025

    When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-34476

    Last Modified: 15 Apr 2025

    ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

    Published: 22 Dec 2022
    4.3
    Medium

    CVE-2022-36315

    Last Modified: 15 Apr 2025

    When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-36320

    Last Modified: 15 Apr 2025

    Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-38475

    Last Modified: 15 Apr 2025

    An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.

    Published: 22 Dec 2022
    3.3
    Low

    CVE-2022-42931

    Last Modified: 15 Apr 2025

    Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

    Published: 22 Dec 2022
    7.5
    High

    CVE-2022-45407

    Last Modified: 15 Apr 2025

    If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.

    Published: 22 Dec 2022
    6.1
    Medium

    CVE-2022-45413

    Last Modified: 15 Apr 2025

    Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.

    Published: 22 Dec 2022
    7.8
    High

    CVE-2022-45415

    Last Modified: 15 Apr 2025

    When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

    Published: 22 Dec 2022
    6.5
    Medium

    CVE-2022-45419

    Last Modified: 15 Apr 2025

    If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.

    Published: 22 Dec 2022
    9.8
    Critical

    CVE-2022-1887

    Last Modified: 16 Apr 2025

    The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-22752

    Last Modified: 18 Apr 2025

    Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 96.

    Published: 22 Dec 2022
    8.8
    High

    CVE-2022-22755

    Last Modified: 16 Apr 2025

    By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.

    Published: 22 Dec 2022