CVE-2022-29914 Reusing existing popups could have allowed for browser spoofing attacks.
Thunderbird and Firefox are not vulnerable if they are using the --force-fullscreen command line argument. All versions of the browser are vulnerable to clickjacking
CVE-2022-22742 Text in edit mode might have lead to exploitable crash.
This issue was fixed in Firefox ESR version 91.5, and Thunderbird version 31.5.
An out-of-bounds read was possible when manipulating arrays
CVE-2022-29910 Firefox for Android would not properly record and persist HSTS settings if it's closed or sent to the background.
On Windows, Linux and Mac computers and in various mobile and remote computing scenarios, a malicious website could bypass the user's HSTS setting
CVE-2022-31741 A crafted CMS message could have led to an invalid memory read, potentially memory corruption
If a user visited a malicious website or opened a malicious file on Windows, an attacker could potentially exploit this vulnerability to access arbitrary system
CVE-2022-36314 When opening a Windows shortcut, an attacker could supply a remote path that leads to unexpected network requests. This bug only affects Firefox for Windows.
It affects Windows Server operating systems that are running Windows Server 2008 or later, but it might not occur on systems that are running Windows
Episode
00:00:00
00:00:00