2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-34474MEDIUM6.1Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect h...
CVE-2022-34473MEDIUM6.1The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however i...
CVE-2022-34472MEDIUM4.3If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, r...
CVE-2022-34471MEDIUM6.5When downloading an update for an addon, the downloaded addon update's version was not verified to match the version sel...
CVE-2022-31746MEDIUM6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. ...
CVE-2022-31745MEDIUM4.3If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnera...
CVE-2022-31744MEDIUM6.5An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so by...
CVE-2022-31743MEDIUM6.5Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. Th...
CVE-2022-31742MEDIUM6.5An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the ...
CVE-2022-31738MEDIUM6.5When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting...
CVE-2022-2226MEDIUM6.5An OpenPGP digital signature includes information about the date when the signature was created. When displaying an emai...
CVE-2022-29916MEDIUM6.5Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. Thi...
CVE-2022-29915MEDIUM4.3The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This ...
CVE-2022-29914MEDIUM6.5When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have e...
CVE-2022-29913MEDIUM6.5The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions...
CVE-2022-29912MEDIUM6.1Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affec...
CVE-2022-29911MEDIUM6.1An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could ...
CVE-2022-29910MEDIUM6.1When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note...
CVE-2022-28287MEDIUM6.5In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. T...
CVE-2022-28286MEDIUM5.4Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user conf...
CVE-2022-28285MEDIUM6.5When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjun...
CVE-2022-28283MEDIUM6.5The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include...
CVE-2022-28282MEDIUM6.5By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object ...
CVE-2022-26386MEDIUM6.5Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>,...
CVE-2022-26385MEDIUM6.5In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now