2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-26485HIGH8.8Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of at...
CVE-2022-26387HIGH7.5When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming t...
CVE-2022-26381HIGH8.8An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploi...
CVE-2022-22764HIGH8.8Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefo...
CVE-2022-22763HIGH8.8When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it shoul...
CVE-2022-22761HIGH8.8Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors d...
CVE-2022-22758HIGH8.8When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone nu...
CVE-2022-22756HIGH8.8If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been...
CVE-2022-22755HIGH8.8By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute J...
CVE-2022-22753HIGH7.1A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write a...
CVE-2022-22752HIGH8.8Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these b...
CVE-2022-22751HIGH8.8Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon ...
CVE-2022-22744HIGH8.8The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This c...
CVE-2022-22741HIGH7.5When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. T...
CVE-2022-22740HIGH8.8Certain network request objects were freed too early when releasing a network request handle. This could have lead to a ...
CVE-2022-22738HIGH8.8Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow ca...
CVE-2022-22737HIGH7.5Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could ha...
CVE-2022-22736HIGH7If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched t...
CVE-2022-22461HIGH7.5 IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could a...
CVE-2022-1802HIGH8.8If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have...
CVE-2022-1529HIGH8.8An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScri...
CVE-2022-0843HIGH8.8Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97...
CVE-2022-0566HIGH8.8It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write o...
CVE-2022-0517HIGH7.8Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileg...
CVE-2022-0511HIGH8.8Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now