CVE-2022-45420

Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

04 Jan 2023, 18:20

Type Values Removed Values Added
First Time Mozilla thunderbird
Mozilla firefox Esr
Mozilla firefox
Mozilla
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://bugzilla.mozilla.org/show_bug.cgi?id=1792643 - (MISC) https://bugzilla.mozilla.org/show_bug.cgi?id=1792643 - Issue Tracking, Permissions Required, Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2022-48/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2022-48/ - Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2022-49/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2022-49/ - Vendor Advisory
References (MISC) https://www.mozilla.org/security/advisories/mfsa2022-47/ - (MISC) https://www.mozilla.org/security/advisories/mfsa2022-47/ - Vendor Advisory
CWE CWE-1021
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

22 Dec 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-22 20:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-45420

Mitre link : CVE-2022-45420

CVE.ORG link : CVE-2022-45420


JSON object : View

Products Affected

mozilla

  • firefox_esr
  • firefox
  • thunderbird
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames