2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36317 | MEDIUM | 6.5 | 0.5% | Dec 22, 2022 | When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this co... |
| CVE-2022-36316 | MEDIUM | 6.1 | 0.3% | Dec 22, 2022 | When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus le... |
| CVE-2022-36315 | MEDIUM | 4.3 | 0.2% | Dec 22, 2022 | When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of prev... |
| CVE-2022-36314 | MEDIUM | 5.5 | 0.2% | Dec 22, 2022 | When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to une... |
| CVE-2022-35646 | MEDIUM | 5.3 | 0.4% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify ... |
| CVE-2022-34485 | CRITICAL | 9.8 | 0.7% | Dec 22, 2022 | Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firef... |
| CVE-2022-34484 | HIGH | 8.8 | 1.0% | Dec 22, 2022 | The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evid... |
| CVE-2022-34483 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti... |
| CVE-2022-34482 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti... |
| CVE-2022-34481 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number... |
| CVE-2022-34480 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer ... |
| CVE-2022-34479 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | A malicious website that could create a popup could have resized the popup to overlay the address bar with its own conte... |
| CVE-2022-34478 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applica... |
| CVE-2022-34477 | HIGH | 7.5 | 0.6% | Dec 22, 2022 | The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however ... |
| CVE-2022-34476 | CRITICAL | 9.8 | 0.7% | Dec 22, 2022 | ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed... |
| CVE-2022-34475 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if atta... |
| CVE-2022-34474 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect h... |
| CVE-2022-34473 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however i... |
| CVE-2022-34472 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, r... |
| CVE-2022-34471 | MEDIUM | 6.5 | 0.2% | Dec 22, 2022 | When downloading an update for an addon, the downloaded addon update's version was not verified to match the version sel... |
| CVE-2022-34470 | CRITICAL | 9.8 | 1.1% | Dec 22, 2022 | Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affec... |
| CVE-2022-34469 | HIGH | 8.1 | 0.4% | Dec 22, 2022 | When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to b... |
| CVE-2022-34468 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This... |
| CVE-2022-31748 | CRITICAL | 9.8 | 0.7% | Dec 22, 2022 | Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported m... |
| CVE-2022-31747 | CRITICAL | 9.8 | 0.9% | Dec 22, 2022 | Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs presen... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now