Search CVE reports


Toggle filters

1171 – 1180 of 3420 results


CVE-2022-34482

Medium priority
Fixed

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing...

1 affected package

firefox

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
Show less packages

CVE-2022-34481

Medium priority
Fixed

In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
thunderbird — — Fixed Fixed Fixed
Show less packages

CVE-2022-34480

Medium priority

Some fixes available 11 of 13

Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.

3 affected packages

firefox, nss, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
nss — — Fixed Fixed Fixed
thunderbird — — Fixed Fixed Ignored
Show less packages

CVE-2022-34479

Medium priority
Fixed

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
thunderbird — — Fixed Fixed Fixed
Show less packages

CVE-2022-34477

Medium priority
Fixed

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks....

1 affected package

firefox

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
Show less packages

CVE-2022-34476

Medium priority
Fixed

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

1 affected package

firefox

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
Show less packages

CVE-2022-34475

Medium priority
Fixed

SVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a...

1 affected package

firefox

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
Show less packages

CVE-2022-34474

Medium priority
Fixed

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This...

1 affected package

firefox

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
Show less packages

CVE-2022-34473

Medium priority
Fixed

The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however it incorrectly did not sanitize <code>xlink:href</code> attributes. This vulnerability affects Firefox < 102.

1 affected package

firefox

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
Show less packages

CVE-2022-34472

Medium priority
Fixed

If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11,...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Not affected Fixed Fixed
thunderbird — — Fixed Fixed Fixed
Show less packages