Vulnérabilités
Vulnérabilités des apps suivies
7 805 CVE touchent une app ou un OS suivi (toutes sévérités, Windows). 214 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 7 805
- Activement exploitées
- 214
- Fenêtre de publication
- 2007-08-28 → 2026-08-18
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2022-28281
HIGH 8.8
1 app
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would hav… |
|
CVE-2022-26387
HIGH 7.5
1 app
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file c… |
|
CVE-2022-26386
MEDIUM 6.5
1 app
Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to downl… |
|
CVE-2022-26384
CRITICAL 9.6
1 app
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a l… |
|
CVE-2022-26383
MEDIUM 4.3
1 app
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Fir… |
|
CVE-2022-26381
HIGH 8.8
1 app
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects… |
|
CVE-2022-22764
HIGH 8.8
1 app
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed e… |
|
CVE-2022-22763
HIGH 8.8
1 app
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability a… |
|
CVE-2022-22761
HIGH 8.8
1 app
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Ex… |
|
CVE-2022-22760
MEDIUM 6.5
1 app
When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-scrip… |
|
CVE-2022-22759
CRITICAL 9.6
1 app
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a Java… |
|
CVE-2022-22756
HIGH 8.8
1 app
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script whic… |
|
CVE-2022-22754
MEDIUM 6.5
1 app
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new … |
|
CVE-2022-22753
HIGH 7.1
1 app
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This c… |
|
CVE-2022-22751
HIGH 8.8
1 app
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memor… |
|
CVE-2022-22748
MEDIUM 6.5
1 app
Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulner… |
|
CVE-2022-22747
MEDIUM 6.5
1 app
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed t… |
|
CVE-2022-22746
MEDIUM 5.9
1 app
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only… |
|
CVE-2022-22745
MEDIUM 6.5
1 app
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefo… |
|
CVE-2022-22744
HIGH 8.8
1 app
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if … |
|
CVE-2022-22743
MEDIUM 4.3
1 app
When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mod… |
|
CVE-2022-22742
MEDIUM 6.5
1 app
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerabil… |
|
CVE-2022-22741
HIGH 7.5
1 app
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR <… |
|
CVE-2022-22740
HIGH 8.8
1 app
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially ex… |
|
CVE-2022-22739
MEDIUM 6.5
1 app
Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.… |
|
CVE-2022-22738
HIGH 8.8
1 app
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. … |
|
CVE-2022-22737
HIGH 7.5
1 app
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a p… |
|
CVE-2022-1834
MEDIUM 6.5
1 app
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displaye… |
|
CVE-2022-1520
MEDIUM 4.3
1 app
When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encr… |
|
CVE-2022-1197
MEDIUM 5.4
1 app
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet r… |
|
CVE-2022-1196
MEDIUM 6.5
1 app
After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnera… |
|
CVE-2022-1097
MEDIUM 6.5
1 app
<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-fre… |
|
CVE-2022-0566
HIGH 8.8
1 app
It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message.… |
|
CVE-2021-4140
CRITICAL 10.0
1 app
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, … |
|
CVE-2021-4129
CRITICAL 9.8
1 app
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safe… |
|
CVE-2021-4127
CRITICAL 9.8
1 app
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and… |
|
CVE-2021-4126
MEDIUM 6.5
1 app
When receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message layer, for example a message footer added by a mailing list … |
|
CVE-2020-15685
HIGH 8.8
1 app
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulner… |
|
CVE-2022-3775
HIGH 7.1
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size.… |
|
CVE-2022-2601
HIGH 8.6
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, all… |
|
CVE-2022-44710
HIGH 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44707
HIGH 6.5
Windows Kernel Denial of Service Vulnerability |
|
CVE-2022-44698
MEDIUM 5.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-44697
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44689
HIGH 7.8
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44683
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44682
HIGH 6.8
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2022-44681
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-44680
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44679
HIGH 6.5
Windows Graphics Component Information Disclosure Vulnerability |