Search CVE reports


Toggle filters

1311 – 1320 of 2812 results


CVE-2022-28281

Medium priority
Fixed

If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Fixed Fixed
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-1196

Medium priority

Some fixes available 6 of 7

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Not in release Ignored
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-1097

Medium priority

Some fixes available 9 of 10

<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects...

2 affected packages

firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — — Fixed Fixed Fixed
thunderbird — — Not affected Fixed Fixed
Show less packages

CVE-2022-24791

Medium priority

Some fixes available 5 of 21

Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are...

7 affected packages

firefox, mozjs38, mozjs52, mozjs68, mozjs78...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox — Fixed Fixed Not in release Ignored
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
mozjs91 — Not in release Ignored Not in release Not in release
thunderbird — Ignored Ignored Not in release Ignored
Show all 7 packages Show less packages

CVE-2022-26387

Medium priority

Some fixes available 16 of 22

When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This...

7 affected packages

mozjs38, mozjs52, firefox-esr, firefox, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox-esr — — — — —
firefox — Fixed Fixed Fixed Fixed
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-26386

Medium priority
Fixed

Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by...

2 affected packages

firefox-esr, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox-esr — — — — —
thunderbird — — Fixed Fixed Fixed
Show less packages

CVE-2022-26384

Medium priority

Some fixes available 16 of 22

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation...

7 affected packages

mozjs38, mozjs52, firefox-esr, firefox, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox-esr — — — — —
firefox — Fixed Fixed Fixed Fixed
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-26383

Medium priority

Some fixes available 16 of 22

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

7 affected packages

mozjs38, mozjs52, firefox-esr, firefox, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox-esr — — — — —
firefox — Fixed Fixed Fixed Fixed
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-26381

Medium priority

Some fixes available 16 of 22

An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

7 affected packages

mozjs38, mozjs52, firefox-esr, firefox, mozjs68...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 — Not in release Not in release Not in release Ignored
mozjs52 — Not in release Not in release Ignored Ignored
firefox-esr — — — — —
firefox — Fixed Fixed Fixed Fixed
mozjs68 — Not in release Not in release Ignored Not in release
mozjs78 — Not in release Ignored Not in release Not in release
thunderbird — Fixed Fixed Fixed Fixed
Show all 7 packages Show less packages

CVE-2022-24713

Medium priority

Some fixes available 11 of 13

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by...

3 affected packages

rust-regex, firefox, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-regex — — Fixed Fixed —
firefox — — Fixed Fixed Fixed
thunderbird — — Not affected Fixed Fixed
Show less packages