2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-3033HIGH8.1If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag...
CVE-2022-38478HIGH8.8Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR ...
CVE-2022-38477HIGH8.8Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firef...
CVE-2022-38476HIGH7.5A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerabilit...
CVE-2022-38473HIGH8.8A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or ...
CVE-2022-36319HIGH7.5When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates tha...
CVE-2022-34484HIGH8.8The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evid...
CVE-2022-34483HIGH8.8An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti...
CVE-2022-34482HIGH8.8An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti...
CVE-2022-34481HIGH8.8In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number...
CVE-2022-34480HIGH8.8Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer ...
CVE-2022-34477HIGH7.5The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however ...
CVE-2022-34469HIGH8.1When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to b...
CVE-2022-34468HIGH8.8An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This...
CVE-2022-31741HIGH8.8A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further ...
CVE-2022-31740HIGH8.8On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a...
CVE-2022-31739HIGH8.8When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly bein...
CVE-2022-2505HIGH8.8Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs s...
CVE-2022-2200HIGH8.8If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScri...
CVE-2022-29918HIGH8.8Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Fi...
CVE-2022-29909HIGH8.8Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origi...
CVE-2022-28289HIGH8.8Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team r...
CVE-2022-28288HIGH8.8Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory s...
CVE-2022-28284HIGH8.8SVG's <code>&lt;use&gt;</code> element could have been used to load unexpected content that could have executed script i...
CVE-2022-28281HIGH8.8If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent pr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now