CVE-2022-36314
Summary
| CVE | CVE-2022-36314 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-22 20:15:00 UTC |
| Updated | 2023-01-03 20:15:00 UTC |
| Description | When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376758 Mozilla Firefox Multiple Vulnerabilities (MFSA2022-28)
- 376759 Mozilla Firefox ESR Multiple Vulnerabilities (MFSA2022-30)
- 376767 Mozilla Thunderbird Multiple Vulnerabilities (MFSA2022-32)
- 502852 Alpine Linux Security Update for firefox-esr
- 502854 Alpine Linux Security Update for firefox
- 505735 Alpine Linux Security Update for firefox-esr
- 505738 Alpine Linux Security Update for firefox
- 752583 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3273-1)
- 752590 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3272-1)
- 752611 SUSE Enterprise Linux Security Update for MozillaFirefox (SUSE-SU-2022:3396-1)
- 753189 SUSE Enterprise Linux Security Update for MozillaThunderbird (SUSE-SU-2022:3281-1)