2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22756 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been... |
| CVE-2022-22755 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute J... |
| CVE-2022-22754 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, ... |
| CVE-2022-22753 | HIGH | 7.1 | 0.6% | Dec 22, 2022 | A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write a... |
| CVE-2022-22752 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these b... |
| CVE-2022-22751 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon ... |
| CVE-2022-22750 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | By generally accepting and passing resource handles across processes, a compromised content process might have confused ... |
| CVE-2022-22749 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.... |
| CVE-2022-22748 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handlin... |
| CVE-2022-22747 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have le... |
| CVE-2022-22746 | MEDIUM | 5.9 | 0.6% | Dec 22, 2022 | A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window s... |
| CVE-2022-22745 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerabi... |
| CVE-2022-22744 | HIGH | 8.8 | 1.3% | Dec 22, 2022 | The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This c... |
| CVE-2022-22743 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the... |
| CVE-2022-22742 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potenti... |
| CVE-2022-22741 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. T... |
| CVE-2022-22740 | HIGH | 8.8 | 1.0% | Dec 22, 2022 | Certain network request objects were freed too early when releasing a network request handle. This could have lead to a ... |
| CVE-2022-22739 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This ... |
| CVE-2022-22738 | HIGH | 8.8 | 1.0% | Dec 22, 2022 | Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow ca... |
| CVE-2022-22737 | HIGH | 7.5 | 0.8% | Dec 22, 2022 | Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could ha... |
| CVE-2022-22736 | HIGH | 7 | 0.2% | Dec 22, 2022 | If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched t... |
| CVE-2022-22461 | HIGH | 7.5 | 0.4% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2022-1887 | CRITICAL | 9.8 | 0.6% | Dec 22, 2022 | The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iO... |
| CVE-2022-1834 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple... |
| CVE-2022-1802 | HIGH | 8.8 | 26.7% | Dec 22, 2022 | If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now