Vulnerabilities > Mozilla > Firefox ESR > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-34479 Unspecified vulnerability in Mozilla Firefox
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks.
network
low complexity
mozilla
6.5
2022-12-22 CVE-2022-36314 Uncontrolled Search Path Element vulnerability in Mozilla Firefox
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows.
local
low complexity
mozilla CWE-427
5.5
2022-12-22 CVE-2022-36318 Race Condition vulnerability in Mozilla Thunderbird
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected.
network
high complexity
mozilla CWE-362
5.3
2022-12-22 CVE-2022-3266 Out-of-bounds Read vulnerability in Mozilla Thunderbird
An out-of-bounds read can occur when decoding H264 video.
local
low complexity
mozilla CWE-125
5.5
2022-12-22 CVE-2022-40956 Cross-site Scripting vulnerability in Mozilla Thunderbird
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead.
network
low complexity
mozilla CWE-79
6.1
2022-12-22 CVE-2022-40957 Unspecified vulnerability in Mozilla Thunderbird
Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM64 platforms.*.
network
low complexity
mozilla
6.5
2022-12-22 CVE-2022-40958 Injection vulnerability in Mozilla Thunderbird
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks.
network
low complexity
mozilla CWE-74
6.5
2022-12-22 CVE-2022-40959 Insecure Storage of Sensitive Information vulnerability in Mozilla Thunderbird
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments.
network
low complexity
mozilla CWE-922
6.5
2022-12-22 CVE-2022-40960 Use After Free vulnerability in Mozilla Thunderbird
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe.
network
low complexity
mozilla CWE-416
6.5
2022-12-22 CVE-2022-42929 Unspecified vulnerability in Mozilla Firefox
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings.
network
low complexity
mozilla
6.5