Search CVE reports


Toggle filters

1231 – 1240 of 2735 results


CVE-2022-28286

Low priority
Fixed

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Fixed Fixed
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-28285

Medium priority

Some fixes available 12 of 20

When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Fixed Fixed
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Fixed Not in release Not in release
thunderbird — Not affected Not affected Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-28282

Medium priority
Fixed

By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Fixed Fixed
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-28281

Medium priority
Fixed

If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Fixed Fixed
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-1196

Medium priority

Some fixes available 6 of 7

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Not in release Ignored
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-1097

Medium priority

Some fixes available 9 of 10

<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Fixed Fixed
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-24791

Medium priority

Some fixes available 5 of 21

Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Not in release Ignored
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Ignored Ignored Not in release Ignored
Show all 7 packages Show less packages

CVE-2022-26387

Medium priority

Some fixes available 16 of 22

When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This...

7 affected packages

mozjs38, mozjs52, firefox-esr, firefox, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox-esr — — — — —
firefox — Fixed Fixed Fixed Fixed
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-26386

Medium priority
Fixed

Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by...

2 affected packages

firefox-esr, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-esr — — — — —
thunderbird — — Fixed Fixed Fixed
Show less packages

CVE-2022-26384

Medium priority

Some fixes available 16 of 22

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation...

7 affected packages

mozjs38, mozjs52, firefox-esr, firefox, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox-esr — — — — —
firefox — Fixed Fixed Fixed Fixed
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages