2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34474 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect h... |
| CVE-2022-34473 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however i... |
| CVE-2022-34472 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, r... |
| CVE-2022-34471 | MEDIUM | 6.5 | 0.2% | Dec 22, 2022 | When downloading an update for an addon, the downloaded addon update's version was not verified to match the version sel... |
| CVE-2022-31746 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. ... |
| CVE-2022-31745 | MEDIUM | 4.3 | 0.3% | Dec 22, 2022 | If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnera... |
| CVE-2022-31744 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so by... |
| CVE-2022-31743 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. Th... |
| CVE-2022-31742 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the ... |
| CVE-2022-31738 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting... |
| CVE-2022-2226 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | An OpenPGP digital signature includes information about the date when the signature was created. When displaying an emai... |
| CVE-2022-29916 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. Thi... |
| CVE-2022-29915 | MEDIUM | 4.3 | 0.3% | Dec 22, 2022 | The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This ... |
| CVE-2022-29914 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have e... |
| CVE-2022-29913 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions... |
| CVE-2022-29912 | MEDIUM | 6.1 | 0.6% | Dec 22, 2022 | Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affec... |
| CVE-2022-29911 | MEDIUM | 6.1 | 0.6% | Dec 22, 2022 | An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could ... |
| CVE-2022-29910 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note... |
| CVE-2022-28287 | MEDIUM | 6.5 | 0.5% | Dec 22, 2022 | In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. T... |
| CVE-2022-28286 | MEDIUM | 5.4 | 0.6% | Dec 22, 2022 | Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user conf... |
| CVE-2022-28285 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjun... |
| CVE-2022-28283 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include... |
| CVE-2022-28282 | MEDIUM | 6.5 | 2.0% | Dec 22, 2022 | By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object ... |
| CVE-2022-26386 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>,... |
| CVE-2022-26385 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now