VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2022-45419MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted.…

  • CVE-2022-45416MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects Firefox ESR < 102.5, Thunderbird <…

  • CVE-2022-45410MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This…

  • CVE-2022-45408MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and…

  • CVE-2022-45405MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Freeing arbitrary nsIInputStream's on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

  • CVE-2022-45404MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Through a series of popup and window.print() calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5,…

  • CVE-2022-45403MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox…

  • CVE-2022-42929MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird…

  • CVE-2022-40961MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.

  • CVE-2022-40960MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

  • CVE-2022-40959MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

  • CVE-2022-40958MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3,…

  • CVE-2022-40957MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

  • CVE-2022-38475MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.

  • CVE-2022-38472MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects…

  • CVE-2022-36317MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denial of Service.*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects…

  • CVE-2022-34479MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. *This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This…

  • CVE-2022-34478MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none…

  • CVE-2022-34471MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior…

  • CVE-2022-31746MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.00

    Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.

Page 73 of 168