Vulnerabilities > Mozilla > Firefox > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-22742 Out-of-bounds Read vulnerability in Mozilla Firefox
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash.
network
low complexity
mozilla CWE-125
6.5
2022-12-22 CVE-2022-22743 Unspecified vulnerability in Mozilla Firefox
When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode.
network
low complexity
mozilla
4.3
2022-12-22 CVE-2022-22745 Unspecified vulnerability in Mozilla Firefox
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations.
network
low complexity
mozilla
6.5
2022-12-22 CVE-2022-22746 Race Condition vulnerability in Mozilla Firefox
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows.
network
high complexity
mozilla CWE-362
5.9
2022-12-22 CVE-2022-22747 Improper Certificate Validation vulnerability in Mozilla Firefox
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash.
network
low complexity
mozilla CWE-295
6.5
2022-12-22 CVE-2022-22748 Unspecified vulnerability in Mozilla Firefox
Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol.
network
low complexity
mozilla
6.5
2022-12-22 CVE-2022-22749 Unspecified vulnerability in Mozilla Firefox
When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.<br>*This bug only affects Firefox for Android.
network
low complexity
mozilla
4.3
2022-12-22 CVE-2022-22750 Unspecified vulnerability in Mozilla Firefox
By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only affects Firefox for Windows and MacOS.
network
low complexity
mozilla
6.5
2022-12-22 CVE-2022-22754 Incorrect Authorization vulnerability in Mozilla Firefox
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions.
network
low complexity
mozilla CWE-863
6.5
2022-12-22 CVE-2022-22757 Origin Validation Error vulnerability in Mozilla Firefox
Remote Agent, used in WebDriver, did not validate the Host or Origin headers.
network
low complexity
mozilla CWE-346
6.5