2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3033 | HIGH | 8.1 | 0.8% | Dec 22, 2022 | If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag... |
| CVE-2022-38478 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR ... |
| CVE-2022-38477 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firef... |
| CVE-2022-38476 | HIGH | 7.5 | 0.8% | Dec 22, 2022 | A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerabilit... |
| CVE-2022-38473 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or ... |
| CVE-2022-36319 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates tha... |
| CVE-2022-34484 | HIGH | 8.8 | 1.0% | Dec 22, 2022 | The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evid... |
| CVE-2022-34483 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti... |
| CVE-2022-34482 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti... |
| CVE-2022-34481 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number... |
| CVE-2022-34480 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer ... |
| CVE-2022-34477 | HIGH | 7.5 | 0.6% | Dec 22, 2022 | The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however ... |
| CVE-2022-34469 | HIGH | 8.1 | 0.4% | Dec 22, 2022 | When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to b... |
| CVE-2022-34468 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This... |
| CVE-2022-31741 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further ... |
| CVE-2022-31740 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a... |
| CVE-2022-31739 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly bein... |
| CVE-2022-2505 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs s... |
| CVE-2022-2200 | HIGH | 8.8 | 23.9% | Dec 22, 2022 | If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScri... |
| CVE-2022-29918 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Fi... |
| CVE-2022-29909 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origi... |
| CVE-2022-28289 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team r... |
| CVE-2022-28288 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory s... |
| CVE-2022-28284 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | SVG's <code><use></code> element could have been used to load unexpected content that could have executed script i... |
| CVE-2022-28281 | HIGH | 8.8 | 2.6% | Dec 22, 2022 | If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent pr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now