2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26485 | HIGH | 8.8 | 14.3% | Dec 22, 2022 | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of at... |
| CVE-2022-26387 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming t... |
| CVE-2022-26381 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploi... |
| CVE-2022-22764 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefo... |
| CVE-2022-22763 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it shoul... |
| CVE-2022-22761 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors d... |
| CVE-2022-22758 | HIGH | 8.8 | 0.4% | Dec 22, 2022 | When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone nu... |
| CVE-2022-22756 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been... |
| CVE-2022-22755 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute J... |
| CVE-2022-22753 | HIGH | 7.1 | 0.6% | Dec 22, 2022 | A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write a... |
| CVE-2022-22752 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these b... |
| CVE-2022-22751 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon ... |
| CVE-2022-22744 | HIGH | 8.8 | 1.3% | Dec 22, 2022 | The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This c... |
| CVE-2022-22741 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. T... |
| CVE-2022-22740 | HIGH | 8.8 | 1.0% | Dec 22, 2022 | Certain network request objects were freed too early when releasing a network request handle. This could have lead to a ... |
| CVE-2022-22738 | HIGH | 8.8 | 1.0% | Dec 22, 2022 | Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow ca... |
| CVE-2022-22737 | HIGH | 7.5 | 0.8% | Dec 22, 2022 | Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could ha... |
| CVE-2022-22736 | HIGH | 7 | 0.2% | Dec 22, 2022 | If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched t... |
| CVE-2022-22461 | HIGH | 7.5 | 0.4% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2022-1802 | HIGH | 8.8 | 26.7% | Dec 22, 2022 | If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have... |
| CVE-2022-1529 | HIGH | 8.8 | 17.1% | Dec 22, 2022 | An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScri... |
| CVE-2022-0843 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97... |
| CVE-2022-0566 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write o... |
| CVE-2022-0517 | HIGH | 7.8 | 0.2% | Dec 22, 2022 | Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileg... |
| CVE-2022-0511 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now