CVE-2022-45418UI Misrepresentation / Clickjacking in Mozilla Firefox

Severity
6.1MEDIUMNVD
OSV8.1OSV6.5
EPSS
0.2%
top 60.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 22
Latest updateFeb 6

Description

If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages9 packages

CVEListV5mozilla/firefoxunspecified107
NVDmozilla/firefox< 107.0
CVEListV5mozilla/firefox_esrunspecified102.5
CVEListV5mozilla/thunderbirdunspecified102.5
NVDmozilla/firefox_esr< 102.5

🔴Vulnerability Details

5
OSV
thunderbird vulnerabilities2023-02-06
GHSA
GHSA-g2g2-6grg-2jm4: If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential2022-12-22
OSV
CVE-2022-45418: If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential2022-12-22
CVEList
CVE-2022-45418: If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential2022-12-22
OSV
firefox vulnerabilities2022-11-16

📋Vendor Advisories

7
Ubuntu
Thunderbird vulnerabilities2023-02-06
Ubuntu
Firefox vulnerabilities2022-11-16
Red Hat
Mozilla: Custom mouse cursor could have been drawn over browser UI2022-11-15
Debian
CVE-2022-45418: firefox - If a custom mouse cursor is specified in CSS, under certain circumstances the cu...2022
Mozilla
Mozilla Foundation Security Advisory 2022-47: CVE-2022-45418
CVE-2022-45418 — UI Misrepresentation / Clickjacking | cvebase