Vulnerabilities
Tracked app vulnerabilities
11,285 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2022-22763
HIGH 8.8
Network 1 apps
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability a… |
|
CVE-2022-22761
HIGH 8.8
Network 1 apps
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Ex… |
|
CVE-2022-22756
HIGH 8.8
Network 1 apps
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script whic… |
|
CVE-2022-22753
HIGH 7.1
Network 1 apps
A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This c… |
|
CVE-2022-22751
HIGH 8.8
Network 1 apps
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memor… |
|
CVE-2022-22744
HIGH 8.8
Network 1 apps
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if … |
|
CVE-2022-22741
HIGH 7.5
Network 1 apps
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR <… |
|
CVE-2022-22740
HIGH 8.8
Network 1 apps
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially ex… |
|
CVE-2022-22738
HIGH 8.8
Network 1 apps
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. … |
|
CVE-2022-22737
HIGH 7.5
Network 1 apps
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a p… |
|
CVE-2022-0566
HIGH 8.8
Network 1 apps
It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing the message.… |
|
CVE-2020-15685
HIGH 8.8
Network 1 apps
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulner… |
|
CVE-2022-3775
HIGH 7.1
Local
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size.… |
|
CVE-2022-2601
HIGH 8.6
Local
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, all… |
|
CVE-2022-44708
HIGH 8.3
Network 1 apps
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
|
CVE-2022-44710
HIGH 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44707
HIGH 6.5
Windows Kernel Denial of Service Vulnerability |
|
CVE-2022-44697
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44689
HIGH 7.8
Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44683
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2022-44682
HIGH 6.8
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2022-44681
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-44680
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44679
HIGH 6.5
Windows Graphics Component Information Disclosure Vulnerability |
|
CVE-2022-44678
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2022-44677
HIGH 7.8
Windows Projected File System Elevation of Privilege Vulnerability |
|
CVE-2022-44675
HIGH 7.8
Windows Bluetooth Driver Elevation of Privilege Vulnerability |
|
CVE-2022-44674
HIGH 5.5
Windows Bluetooth Driver Information Disclosure Vulnerability |
|
CVE-2022-44673
HIGH 7.0
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability |
|
CVE-2022-44671
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-44669
HIGH 7.0
Windows Error Reporting Elevation of Privilege Vulnerability |
|
CVE-2022-44668
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2022-44667
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2022-44666
HIGH 7.8
Windows Contacts Remote Code Execution Vulnerability |
|
CVE-2022-41121
HIGH 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2022-41094
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2022-41077
HIGH 7.8
Windows Fax Compose Form Elevation of Privilege Vulnerability |
|
CVE-2022-41074
HIGH 5.5
Windows Graphics Component Information Disclosure Vulnerability |
|
CVE-2022-42772
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42771
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42770
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42756
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42755
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-42754
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-39134
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-39133
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-39132
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-39131
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-39130
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-39129
HIGH
Indexed via Android Security Bulletin; full NVD metadata pending. |