2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46873 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject marku... |
| CVE-2022-46872 | HIGH | 8.6 | 0.8% | Dec 22, 2022 | An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipb... |
| CVE-2022-46871 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability af... |
| CVE-2022-45421 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some o... |
| CVE-2022-45420 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of t... |
| CVE-2022-45419 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server th... |
| CVE-2022-45418 | MEDIUM | 6.1 | 0.7% | Dec 22, 2022 | If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the brow... |
| CVE-2022-45417 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers bei... |
| CVE-2022-45416 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing... |
| CVE-2022-45415 | HIGH | 7.8 | 0.2% | Dec 22, 2022 | When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox ... |
| CVE-2022-45414 | HIGH | 8.1 | 0.5% | Dec 22, 2022 | If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a ... |
| CVE-2022-45413 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause ... |
| CVE-2022-45412 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink... |
| CVE-2022-45411 | MEDIUM | 6.1 | 0.6% | Dec 22, 2022 | Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access ... |
| CVE-2022-45410 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the Se... |
| CVE-2022-45409 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> m... |
| CVE-2022-45408 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seein... |
| CVE-2022-45407 | HIGH | 7.5 | 0.6% | Dec 22, 2022 | If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred,... |
| CVE-2022-45406 | CRITICAL | 9.8 | 1.1% | Dec 22, 2022 | If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while refere... |
| CVE-2022-45405 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free a... |
| CVE-2022-45404 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without... |
| CVE-2022-45403 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for ... |
| CVE-2022-42932 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firef... |
| CVE-2022-42931 | LOW | 3.3 | 0.1% | Dec 22, 2022 | Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk.... |
| CVE-2022-42930 | HIGH | 7.1 | 0.4% | Dec 22, 2022 | If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUt... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now