Vulnérabilités
Vulnérabilités des apps suivies
7 805 CVE touchent une app ou un OS suivi (toutes sévérités, Windows). 214 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 7 805
- Activement exploitées
- 214
- Fenêtre de publication
- 2007-08-28 → 2026-08-18
7 805 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2022-42927
HIGH 8.1
Réseau 1 app
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This… |
|
CVE-2022-40962
HIGH 8.8
Réseau 1 app
Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox… |
|
CVE-2022-40960
MEDIUM 6.5
Réseau 1 app
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vul… |
|
CVE-2022-40959
MEDIUM 6.5
Réseau 1 app
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted su… |
|
CVE-2022-40958
MEDIUM 6.5
Réseau 1 app
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies fro… |
|
CVE-2022-40957
MEDIUM 6.5
Réseau 1 app
Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM… |
|
CVE-2022-40956
MEDIUM 6.1
Réseau 1 app
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability … |
|
CVE-2022-3266
MEDIUM 5.5
Local 1 app
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thun… |
|
CVE-2022-3155
HIGH 7.8
Local 1 app
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an a… |
|
CVE-2022-3034
MEDIUM 4.3
Réseau 1 app
When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, … |
|
CVE-2022-38478
HIGH 8.8
Réseau 1 app
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed eviden… |
|
CVE-2022-38477
HIGH 8.8
Réseau 1 app
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed… |
|
CVE-2022-38476
HIGH 7.5
Réseau 1 app
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the … |
|
CVE-2022-3033
HIGH 8.1
Réseau 1 app
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"<… |
|
CVE-2022-3032
MEDIUM 6.5
Réseau 1 app
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remot… |
|
CVE-2022-38473
HIGH 8.8
Réseau 1 app
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affe… |
|
CVE-2022-38472
MEDIUM 6.5
Réseau 1 app
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This cou… |
|
CVE-2022-36319
HIGH 7.5
Réseau 1 app
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects… |
|
CVE-2022-36318
MEDIUM 5.3
Réseau 1 app
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox E… |
|
CVE-2022-36314
MEDIUM 5.5
Local 1 app
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the opera… |
|
CVE-2022-34484
HIGH 8.8
Réseau 1 app
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presum… |
|
CVE-2022-34481
HIGH 8.8
Réseau 1 app
In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large f… |
|
CVE-2022-34479
MEDIUM 6.5
Réseau 1 app
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusi… |
|
CVE-2022-34478
MEDIUM 6.5
Réseau 1 app
The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a us… |
|
CVE-2022-34472
MEDIUM 4.3
Réseau 1 app
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being… |
|
CVE-2022-34470
CRITICAL 9.8
Réseau 1 app
Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, … |
|
CVE-2022-34468
HIGH 8.8
Réseau 1 app
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, F… |
|
CVE-2022-31747
CRITICAL 9.8
Réseau 1 app
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. … |
|
CVE-2022-31744
MEDIUM 6.5
Réseau 1 app
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. … |
|
CVE-2022-31742
MEDIUM 6.5
Réseau 1 app
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles … |
|
CVE-2022-31741
HIGH 8.8
Réseau 1 app
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability a… |
|
CVE-2022-31740
HIGH 8.8
Réseau 1 app
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vu… |
|
CVE-2022-31739
HIGH 8.8
Réseau 1 app
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths th… |
|
CVE-2022-31738
MEDIUM 6.5
Réseau 1 app
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofin… |
|
CVE-2022-31737
CRITICAL 9.8
Réseau 1 app
A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability aff… |
|
CVE-2022-31736
CRITICAL 9.8
Réseau 1 app
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firef… |
|
CVE-2022-2505
HIGH 8.8
Réseau 1 app
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and… |
|
CVE-2022-2226
MEDIUM 6.5
Réseau 1 app
An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, th… |
|
CVE-2022-2200
HIGH 8.8
Réseau 1 app
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code e… |
|
CVE-2022-29917
CRITICAL 9.8
Réseau 1 app
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR… |
|
CVE-2022-29916
MEDIUM 6.5
Réseau 1 app
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the bro… |
|
CVE-2022-29914
MEDIUM 6.5
Réseau 1 app
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This v… |
|
CVE-2022-29913
MEDIUM 6.5
Réseau 1 app
The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerabili… |
|
CVE-2022-29912
MEDIUM 6.1
Réseau 1 app
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91… |
|
CVE-2022-29911
MEDIUM 6.1
Réseau 1 app
An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>… |
|
CVE-2022-29909
HIGH 8.8
Réseau 1 app
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wr… |
|
CVE-2022-28289
HIGH 8.8
Réseau 1 app
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in T… |
|
CVE-2022-28286
MEDIUM 5.4
Réseau 1 app
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnera… |
|
CVE-2022-28285
MEDIUM 6.5
Réseau 1 app
When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this c… |
|
CVE-2022-28282
MEDIUM 6.5
Réseau 1 app
By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then re… |