Vulnerabilities > Mozilla > Thunderbird

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-22753 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Mozilla Firefox
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory.
network
high complexity
mozilla CWE-367
7.1
2022-12-22 CVE-2022-22754 Incorrect Authorization vulnerability in Mozilla Firefox
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions.
network
low complexity
mozilla CWE-863
6.5
2022-12-22 CVE-2022-22756 Unspecified vulnerability in Mozilla Firefox
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it.
network
low complexity
mozilla
8.8
2022-12-22 CVE-2022-22759 Unspecified vulnerability in Mozilla Firefox
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g.
network
low complexity
mozilla
critical
9.6
2022-12-22 CVE-2022-22760 Information Exposure Through an Error Message vulnerability in Mozilla Firefox
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses.
network
low complexity
mozilla CWE-209
6.5
2022-12-22 CVE-2022-22761 Unspecified vulnerability in Mozilla Firefox
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy.
network
low complexity
mozilla
8.8
2022-12-22 CVE-2022-22763 Unspecified vulnerability in Mozilla Firefox
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible.
network
low complexity
mozilla
8.8
2022-12-22 CVE-2022-22764 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-26381 Use After Free vulnerability in Mozilla Firefox
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash.
network
low complexity
mozilla CWE-416
8.8
2022-12-22 CVE-2022-26383 Unspecified vulnerability in Mozilla Firefox
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification.
network
low complexity
mozilla
4.3