Vulnerabilities
Tracked app vulnerabilities
11,291 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2022-33276
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33274
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33266
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33255
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33253
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-33252
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-32637
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-32636
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-32635
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-2959
HIGH 7.0
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-25746
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-25725
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-23960
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20494
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20493
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20492
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20490
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20489
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20461
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20456
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-20235
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-46881
HIGH 8.8
Network 1 apps
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was ad… |
|
CVE-2022-46878
HIGH 8.8
Network 1 apps
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of th… |
|
CVE-2022-46874
HIGH 8.8
Network 1 apps
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potenti… |
|
CVE-2022-46872
HIGH 8.6
Network 1 apps
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug… |
|
CVE-2022-45421
HIGH 8.8
Network 1 apps
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory … |
|
CVE-2022-45414
HIGH 8.1
Network 1 apps
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or … |
|
CVE-2022-45412
HIGH 8.8
Network 1 apps
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing un… |
|
CVE-2022-45409
HIGH 8.8
Network 1 apps
The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a u… |
|
CVE-2022-42932
HIGH 8.8
Network 1 apps
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed… |
|
CVE-2022-42928
HIGH 8.8
Network 1 apps
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potent… |
|
CVE-2022-42927
HIGH 8.1
Network 1 apps
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This… |
|
CVE-2022-40962
HIGH 8.8
Network 1 apps
Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox… |
|
CVE-2022-3155
HIGH 7.8
Local 1 apps
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an a… |
|
CVE-2022-38478
HIGH 8.8
Network 1 apps
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed eviden… |
|
CVE-2022-38477
HIGH 8.8
Network 1 apps
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed… |
|
CVE-2022-38476
HIGH 7.5
Network 1 apps
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the … |
|
CVE-2022-3033
HIGH 8.1
Network 1 apps
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"<… |
|
CVE-2022-38473
HIGH 8.8
Network 1 apps
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affe… |
|
CVE-2022-36319
HIGH 7.5
Network 1 apps
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects… |
|
CVE-2022-34484
HIGH 8.8
Network 1 apps
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presum… |
|
CVE-2022-34481
HIGH 8.8
Network 1 apps
In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large f… |
|
CVE-2022-34468
HIGH 8.8
Network 1 apps
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, F… |
|
CVE-2022-31741
HIGH 8.8
Network 1 apps
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability a… |
|
CVE-2022-31740
HIGH 8.8
Network 1 apps
On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vu… |
|
CVE-2022-31739
HIGH 8.8
Network 1 apps
When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths th… |
|
CVE-2022-2505
HIGH 8.8
Network 1 apps
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and… |
|
CVE-2022-2200
HIGH 8.8
Network 1 apps
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code e… |
|
CVE-2022-29909
HIGH 8.8
Network 1 apps
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wr… |
|
CVE-2022-28289
HIGH 8.8
Network 1 apps
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in T… |