Lucene search

K
cvelistMozillaCVELIST:CVE-2022-45420
HistoryDec 22, 2022 - 12:00 a.m.

CVE-2022-45420

2022-12-2200:00:00
mozilla
www.cve.org
6
iframe
attacker
user confusion
spoofing attacks
firefox esr
thunderbird
firefox
cve-2022-45420

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

43.1%

Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CNA Affected

[
  {
    "vendor": "Mozilla",
    "product": "Firefox ESR",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "102.5",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Mozilla",
    "product": "Thunderbird",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "102.5",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Mozilla",
    "product": "Firefox",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "107",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]