CVE-2022-22763 When a worker is shutdown, it is possible to cause script to run late in the lifecycle.
It does not affect Windows or OS X versions ofThunderbird or Firefox. Workarounds for this will be available until a new stable version is released.
CVE-2022-34468 An iframe with scripts that are disabled could run scripts if the user clicks a code>javascript:/code> link.
This issue was fixed in Firefox 102, Thunderbird 102, and Thunderbird 91.11. Users of Firefox 66 and Firefox ESR 52 on Windows who visit
CVE-2022-29917 Mozilla developers found memory safety bugs in Firefox 99 and Firefox ESR 91.8.
This issue was fixed in Thunderbird 24.3.0.1, ESR 24.3.0.1, and Firefox 27.0.1. If you are running any
CVE-2022-36315 Subresource Integrity protects against script reuse when an injection attack occurs.
If the integrity service is enabled for a script, it can be triggered by injecting a fake script that appears to come from a trusted
CVE-2022-22740 Network request handles were freed too early which could lead to a use after free and exploitable crash.
We have fixed this issue in the latest ESR and FF versions. We no longer free network request handles during shutdown, which prevents the use-
Episode
00:00:00
00:00:00