2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28288 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory s... |
| CVE-2022-28287 | MEDIUM | 6.5 | 0.5% | Dec 22, 2022 | In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. T... |
| CVE-2022-28286 | MEDIUM | 5.4 | 0.6% | Dec 22, 2022 | Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user conf... |
| CVE-2022-28285 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjun... |
| CVE-2022-28284 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | SVG's <code><use></code> element could have been used to load unexpected content that could have executed script i... |
| CVE-2022-28283 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include... |
| CVE-2022-28282 | MEDIUM | 6.5 | 2.0% | Dec 22, 2022 | By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object ... |
| CVE-2022-28281 | HIGH | 8.8 | 2.6% | Dec 22, 2022 | If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent pr... |
| CVE-2022-26486 | CRITICAL | 9.6 | 2.3% | Dec 22, 2022 | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have... |
| CVE-2022-26485 | HIGH | 8.8 | 13.8% | Dec 22, 2022 | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of at... |
| CVE-2022-26387 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming t... |
| CVE-2022-26386 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>,... |
| CVE-2022-26385 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to ... |
| CVE-2022-26384 | CRITICAL | 9.6 | 0.9% | Dec 22, 2022 | If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scri... |
| CVE-2022-26383 | MEDIUM | 4.3 | 0.7% | Dec 22, 2022 | When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This ... |
| CVE-2022-26382 | MEDIUM | 4.3 | 0.5% | Dec 22, 2022 | While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fo... |
| CVE-2022-26381 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploi... |
| CVE-2022-22764 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefo... |
| CVE-2022-22763 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it shoul... |
| CVE-2022-22762 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un... |
| CVE-2022-22761 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors d... |
| CVE-2022-22760 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | When importing resources using Web Workers, error messages would distinguish the difference between <code>application/ja... |
| CVE-2022-22759 | CRITICAL | 9.6 | 0.7% | Dec 22, 2022 | If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the... |
| CVE-2022-22758 | HIGH | 8.8 | 0.4% | Dec 22, 2022 | When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone nu... |
| CVE-2022-22757 | MEDIUM | 6.5 | 0.2% | Dec 22, 2022 | Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connec... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now