2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42929 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may p... |
| CVE-2022-42928 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have... |
| CVE-2022-42927 | HIGH | 8.1 | 0.4% | Dec 22, 2022 | A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirec... |
| CVE-2022-40962 | HIGH | 8.8 | 1.3% | Dec 22, 2022 | Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reporte... |
| CVE-2022-40961 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially ex... |
| CVE-2022-40960 | MEDIUM | 6.5 | 0.9% | Dec 22, 2022 | Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a ... |
| CVE-2022-40959 | MEDIUM | 6.5 | 1.3% | Dec 22, 2022 | During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leak... |
| CVE-2022-40958 | MEDIUM | 6.5 | 1.1% | Dec 22, 2022 | By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context c... |
| CVE-2022-40957 | MEDIUM | 6.5 | 1.1% | Dec 22, 2022 | Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<b... |
| CVE-2022-40956 | MEDIUM | 6.1 | 0.9% | Dec 22, 2022 | When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected elem... |
| CVE-2022-3266 | MEDIUM | 5.5 | 0.3% | Dec 22, 2022 | An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerab... |
| CVE-2022-3155 | HIGH | 7.8 | 0.2% | Dec 22, 2022 | When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the recei... |
| CVE-2022-3034 | MEDIUM | 4.3 | 0.5% | Dec 22, 2022 | When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to ... |
| CVE-2022-3033 | HIGH | 8.1 | 0.8% | Dec 22, 2022 | If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag... |
| CVE-2022-3032 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute t... |
| CVE-2022-38478 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR ... |
| CVE-2022-38477 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firef... |
| CVE-2022-38476 | HIGH | 7.5 | 0.8% | Dec 22, 2022 | A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerabilit... |
| CVE-2022-38475 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was ze... |
| CVE-2022-38474 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | A website that had permission to access the microphone could record audio without the audio notification being shown. Th... |
| CVE-2022-38473 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or ... |
| CVE-2022-38472 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was... |
| CVE-2022-36320 | CRITICAL | 9.8 | 0.7% | Dec 22, 2022 | Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs s... |
| CVE-2022-36319 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates tha... |
| CVE-2022-36318 | MEDIUM | 5.3 | 0.5% | Dec 22, 2022 | When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now