Search CVE reports


Toggle filters

1121 – 1130 of 3420 results


CVE-2022-45415

Medium priority
Ignored

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 7 packages Show less packages

CVE-2022-45413

Medium priority

Some fixes available 2 of 11

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Fixed Fixed
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 7 packages Show less packages

CVE-2022-45412

Medium priority

Some fixes available 7 of 15

When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-45411

Medium priority

Some fixes available 7 of 15

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-45410

Medium priority

Some fixes available 7 of 15

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-45409

Medium priority

Some fixes available 7 of 15

The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-45408

Medium priority

Some fixes available 7 of 15

Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-45407

Medium priority
Ignored

If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Not affected Not affected Not in release Ignored
Show all 7 packages Show less packages

CVE-2022-45406

Medium priority

Some fixes available 7 of 15

If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-45405

Medium priority

Some fixes available 7 of 15

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Not affected Not affected Not in release Not affected
mozjs38 — — Not in release Not in release Ignored
mozjs52 — — Not in release Ignored Ignored
mozjs68 — — Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — — Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages