QID 376705
Date Published: 2022-06-29
QID 376705: Mozilla Firefox Multiple Vulnerabilities (MFSA2022-24)
Firefox is a free and open-source web browser developed for Windows, OS X, and Linux, with a mobile version for Android.
Mozilla Firefox is prone to
CVE-2022-34479: A popup window could be resized in a way to overlay the address bar with web content
CVE-2022-34470: Use-after-free in nsSHistory
CVE-2022-34468: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI
CVE-2022-34482: Drag and drop of malicious image could have led to malicious executable and potential code execution
CVE-2022-34483: Drag and drop of malicious image could have led to malicious executable and potential code execution
CVE-2022-34476: ASN.1 parser could have been tricked into accepting malformed ASN.1
CVE-2022-34481: Potential integer overflow in ReplaceElementsAt
CVE-2022-34474: Sandboxed iframes could redirect to external schemes
CVE-2022-34469: TLS certificate errors on HSTS-protected domains could be bypassed by the user on Firefox for Android
CVE-2022-34471: Compromised server could trick a browser into an addon downgrade
CVE-2022-34472: Unavailable PAC file resulted in OCSP requests being blocked
CVE-2022-34478: Microsoft protocols can be attacked if a user accepts a prompt
CVE-2022-2200: Undesired attributes could be set as part of prototype pollution
CVE-2022-34480: Free of uninitialized pointer in lg_init
CVE-2022-34477: MediaError message property leaked information on cross-origin same-site pages
CVE-2022-34475: HTML Sanitizer could have been bypassed via same-origin script via use tags
CVE-2022-34473: HTML Sanitizer could have been bypassed via use tags
CVE-2022-34484: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11
CVE-2022-34485: Memory safety bugs fixed in Firefox 102
Affected Products:
Prior to Firefox 102
QID Detection Logic (Authenticated) :
This checks for vulnerable version of Firefox browser.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
- MFSA2022-24 -
www.mozilla.org/en-US/security/advisories/mfsa2022-24/
CVEs related to QID 376705
Advisory ID | Software | Component | Link |
---|---|---|---|
MFSA2022-24 |
![]() |