Vulnerabilities > Mozilla > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-22 | CVE-2022-1196 | Use After Free vulnerability in Mozilla Firefox ESR After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. | 6.5 |
2022-12-22 | CVE-2022-1197 | Improper Certificate Validation vulnerability in Mozilla Thunderbird When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. | 5.4 |
2022-12-22 | CVE-2022-1520 | Unspecified vulnerability in Mozilla Thunderbird When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encryption or signature status. | 4.3 |
2022-12-22 | CVE-2022-1834 | Improper Certificate Validation vulnerability in Mozilla Thunderbird When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displayed all the spaces. | 6.5 |
2022-12-22 | CVE-2022-22739 | Unspecified vulnerability in Mozilla Firefox Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. | 6.5 |
2022-12-22 | CVE-2022-22742 | Out-of-bounds Read vulnerability in Mozilla Firefox When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. | 6.5 |
2022-12-22 | CVE-2022-22743 | Unspecified vulnerability in Mozilla Firefox When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. | 4.3 |
2022-12-22 | CVE-2022-22745 | Unspecified vulnerability in Mozilla Firefox Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. | 6.5 |
2022-12-22 | CVE-2022-22746 | Race Condition vulnerability in Mozilla Firefox A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. | 5.9 |
2022-12-22 | CVE-2022-22747 | Improper Certificate Validation vulnerability in Mozilla Firefox After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. | 6.5 |