cbcvebase.
CVE-2022-22746
published 2022-12-22

CVE-2022-22746: A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only…

PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.59%
44.7th percentile
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianfirefox
debianfirefox-esr
debianthunderbird
mozillafirefox< 96.096.0
mozillafirefox
mozillafirefox>= unspecified < 9696
mozillafirefox_esr< 91.591.5
mozillafirefox_esr>= unspecified < 91.591.5
mozillathunderbird< 91.591.5
mozillathunderbird>= unspecified < 91.591.5

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.