2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-46873HIGH8.8Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject marku...
CVE-2022-46872HIGH8.6An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipb...
CVE-2022-46871HIGH8.8An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability af...
CVE-2022-45421HIGH8.8Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some o...
CVE-2022-45420MEDIUM6.5Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of t...
CVE-2022-45419MEDIUM6.5If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server th...
CVE-2022-45418MEDIUM6.1If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the brow...
CVE-2022-45417MEDIUM4.3Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers bei...
CVE-2022-45416MEDIUM6.5Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing...
CVE-2022-45415HIGH7.8When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox ...
CVE-2022-45414HIGH8.1If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a ...
CVE-2022-45413MEDIUM6.1Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause ...
CVE-2022-45412HIGH8.8When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink...
CVE-2022-45411MEDIUM6.1Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access ...
CVE-2022-45410MEDIUM6.5When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the Se...
CVE-2022-45409HIGH8.8The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> m...
CVE-2022-45408MEDIUM6.5Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seein...
CVE-2022-45407HIGH7.5If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred,...
CVE-2022-45406CRITICAL9.8If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while refere...
CVE-2022-45405MEDIUM6.5Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free a...
CVE-2022-45404MEDIUM6.5Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without...
CVE-2022-45403MEDIUM6.5Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for ...
CVE-2022-42932HIGH8.8Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firef...
CVE-2022-42931LOW3.3Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk....
CVE-2022-42930HIGH7.1If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUt...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now