2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45405 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free a... |
| CVE-2022-45404 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without... |
| CVE-2022-45403 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for ... |
| CVE-2022-42929 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may p... |
| CVE-2022-40961 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially ex... |
| CVE-2022-40960 | MEDIUM | 6.5 | 0.9% | Dec 22, 2022 | Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a ... |
| CVE-2022-40959 | MEDIUM | 6.5 | 1.3% | Dec 22, 2022 | During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leak... |
| CVE-2022-40958 | MEDIUM | 6.5 | 1.1% | Dec 22, 2022 | By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context c... |
| CVE-2022-40957 | MEDIUM | 6.5 | 1.1% | Dec 22, 2022 | Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<b... |
| CVE-2022-40956 | MEDIUM | 6.1 | 0.9% | Dec 22, 2022 | When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected elem... |
| CVE-2022-3266 | MEDIUM | 5.5 | 0.3% | Dec 22, 2022 | An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerab... |
| CVE-2022-3034 | MEDIUM | 4.3 | 0.5% | Dec 22, 2022 | When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to ... |
| CVE-2022-3032 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute t... |
| CVE-2022-38475 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was ze... |
| CVE-2022-38474 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | A website that had permission to access the microphone could record audio without the audio notification being shown. Th... |
| CVE-2022-38472 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was... |
| CVE-2022-36318 | MEDIUM | 5.3 | 0.5% | Dec 22, 2022 | When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability... |
| CVE-2022-36317 | MEDIUM | 6.5 | 0.5% | Dec 22, 2022 | When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this co... |
| CVE-2022-36316 | MEDIUM | 6.1 | 0.3% | Dec 22, 2022 | When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus le... |
| CVE-2022-36315 | MEDIUM | 4.3 | 0.2% | Dec 22, 2022 | When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of prev... |
| CVE-2022-36314 | MEDIUM | 5.5 | 0.2% | Dec 22, 2022 | When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to une... |
| CVE-2022-35646 | MEDIUM | 5.3 | 0.4% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify ... |
| CVE-2022-34479 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | A malicious website that could create a popup could have resized the popup to overlay the address bar with its own conte... |
| CVE-2022-34478 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applica... |
| CVE-2022-34475 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if atta... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now