2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28288HIGH8.8Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory s...
CVE-2022-28287MEDIUM6.5In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. T...
CVE-2022-28286MEDIUM5.4Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user conf...
CVE-2022-28285MEDIUM6.5When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjun...
CVE-2022-28284HIGH8.8SVG's <code>&lt;use&gt;</code> element could have been used to load unexpected content that could have executed script i...
CVE-2022-28283MEDIUM6.5The sourceMapURL feature in devtools was missing security checks that would have allowed a webpage to attempt to include...
CVE-2022-28282MEDIUM6.5By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object ...
CVE-2022-28281HIGH8.8If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent pr...
CVE-2022-26486CRITICAL9.6An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have...
CVE-2022-26485HIGH8.8Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of at...
CVE-2022-26387HIGH7.5When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming t...
CVE-2022-26386MEDIUM6.5Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>,...
CVE-2022-26385MEDIUM6.5In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to ...
CVE-2022-26384CRITICAL9.6If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scri...
CVE-2022-26383MEDIUM4.3When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This ...
CVE-2022-26382MEDIUM4.3While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fo...
CVE-2022-26381HIGH8.8An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploi...
CVE-2022-22764HIGH8.8Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefo...
CVE-2022-22763HIGH8.8When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it shoul...
CVE-2022-22762MEDIUM4.3Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un...
CVE-2022-22761HIGH8.8Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors d...
CVE-2022-22760MEDIUM6.5When importing resources using Web Workers, error messages would distinguish the difference between <code>application/ja...
CVE-2022-22759CRITICAL9.6If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the...
CVE-2022-22758HIGH8.8When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone nu...
CVE-2022-22757MEDIUM6.5Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connec...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now