Kaspersky ID:
KLA12520
Дата обнаружения:
03/05/2022
Обновлено:
22/01/2024

Описание

Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to execute arbitrary code, gain privileges, bypass security restrictions, spoof user interface, obtain sensitive information.

Below is a complete list of vulnerabilities:

  1. Memory safety vulnerability can be exploited to execute arbitrary code.
  2. An elevation of privilege vulnerability in iframe Sandbox can be exploited remotely to gain privileges.
  3. Bypassing permission prompt in nested browsing contexts can be exploited to bypass security restrictions.
  4. Leaking cross-origin redirect can be exploited to bypass security restrictions.
  5. Fullscreen notification bypass using popups can be exploited to spoof user interface.
  6. Security vulnerability in reader mode can be exploited to bypass security restrictions.
  7. Security vulnerability can be exploited to bypass security restrictions.
  8. Leaking browser history with CSS variables can be exploited to obtain sensitive information.

Первичный источник обнаружения

Связанные продукты

Список CVE

  • CVE-2022-29917
    warning
  • CVE-2022-29911
    warning
  • CVE-2022-29909
    warning
  • CVE-2022-29915
    warning
  • CVE-2022-29914
    warning
  • CVE-2022-29918
    warning
  • CVE-2022-29912
    warning
  • CVE-2022-29910
    warning
  • CVE-2022-29916
    warning

Смотрите также

Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com

Нашли неточность в описании этой уязвимости? Дайте нам знать!
Kaspersky IT Security Calculator:
Оцените ваш профиль кибербезопасности
Узнать больше
Встречай новый Kaspersky!
Каждая минута твоей онлайн-жизни заслуживает топовой защиты.
Узнать больше
Confirm changes?
Your message has been sent successfully.