Vulnerabilities > Mozilla > Firefox ESR > High

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-31741 Use of Uninitialized Resource vulnerability in Mozilla Firefox
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption.
network
low complexity
mozilla CWE-908
8.8
2022-12-22 CVE-2022-34468 Unspecified vulnerability in Mozilla Firefox
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link.
network
low complexity
mozilla
8.8
2022-12-22 CVE-2022-34481 Integer Overflow or Wraparound vulnerability in Mozilla Firefox
In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large for the container.
network
low complexity
mozilla CWE-190
8.8
2022-12-22 CVE-2022-34484 Use After Free vulnerability in Mozilla Firefox
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10.
network
low complexity
mozilla CWE-416
8.8
2022-12-22 CVE-2022-36319 Unspecified vulnerability in Mozilla Thunderbird
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed.
network
low complexity
mozilla
7.5
2022-12-22 CVE-2022-38473 Improper Preservation of Permissions vulnerability in Mozilla Thunderbird
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access).
network
low complexity
mozilla CWE-281
8.8
2022-12-22 CVE-2022-38476 Use After Free vulnerability in Mozilla Thunderbird
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability.
network
high complexity
mozilla CWE-416
7.5
2022-12-22 CVE-2022-38477 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-38478 Out-of-bounds Write vulnerability in Mozilla Thunderbird
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-40962 Out-of-bounds Write vulnerability in Mozilla Thunderbird
Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 104 and Firefox ESR 102.2.
network
low complexity
mozilla CWE-787
8.8