Vulnerabilities > Mozilla > Firefox ESR > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-22 | CVE-2022-28286 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox ESR Due to a layout change, iframe contents could have been rendered outside of its border. | 5.4 |
2022-12-22 | CVE-2022-29911 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Thunderbird An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. | 6.1 |
2022-12-22 | CVE-2022-29912 | Open Redirect vulnerability in Mozilla Thunderbird Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. | 6.1 |
2022-12-22 | CVE-2022-29914 | Unspecified vulnerability in Mozilla Thunderbird When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. | 6.5 |
2022-12-22 | CVE-2022-29916 | Unspecified vulnerability in Mozilla Thunderbird Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. | 6.5 |
2022-12-22 | CVE-2022-31738 | Authentication Bypass by Spoofing vulnerability in Mozilla Firefox When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. | 6.5 |
2022-12-22 | CVE-2022-31742 | Unspecified vulnerability in Mozilla Firefox An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. | 6.5 |
2022-12-22 | CVE-2022-31744 | Cross-site Scripting vulnerability in Mozilla Firefox ESR An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. | 6.5 |
2022-12-22 | CVE-2022-34472 | Unspecified vulnerability in Mozilla Firefox If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. | 4.3 |
2022-12-22 | CVE-2022-34478 | Unspecified vulnerability in Mozilla Firefox The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. | 6.5 |