Vulnerabilities > Mozilla
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-22 | CVE-2022-31740 | Unspecified vulnerability in Mozilla Firefox ESR On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. | 8.8 |
2022-12-22 | CVE-2022-31741 | Use of Uninitialized Resource vulnerability in Mozilla Firefox A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. | 8.8 |
2022-12-22 | CVE-2022-31742 | Unspecified vulnerability in Mozilla Firefox An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. | 6.5 |
2022-12-22 | CVE-2022-31743 | Cross-site Scripting vulnerability in Mozilla Firefox Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. | 6.5 |
2022-12-22 | CVE-2022-31744 | Cross-site Scripting vulnerability in Mozilla Firefox ESR An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. | 6.5 |
2022-12-22 | CVE-2022-31745 | Improper Validation of Array Index vulnerability in Mozilla Firefox If array shift operations are not used, the Garbage Collector may have become confused about valid objects. | 4.3 |
2022-12-22 | CVE-2022-31746 | Information Exposure vulnerability in Mozilla Firefox Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. | 6.5 |
2022-12-22 | CVE-2022-31747 | Use After Free vulnerability in Mozilla Firefox Mozilla developers Andrew McCreight, Nicolas B. | 9.8 |
2022-12-22 | CVE-2022-31748 | Unspecified vulnerability in Mozilla Firefox Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. | 9.8 |
2022-12-22 | CVE-2022-34468 | Unspecified vulnerability in Mozilla Firefox An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. | 8.8 |