RHSA-2022:0514HighCVSS 9.6
Red Hat Security Advisory: firefox security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2022-22754 — Mozilla: Extensions could have bypassed permission confirmation during update CVE-2022-22756 — Mozilla: Drag and dropping an image could have resulted in the dropped object being an executable CVE-2022-22759 — Mozilla: Sandboxed iframes could have executed script if the parent appended elements CVE-2022-22760 — Mozilla: Cross-Origin responses could be distinguished between script and non-script content-types CVE-2022-22761 — Mozilla: frame-ancestors Content Security Policy directive was not enforced for framed extension pages CVE-2022-22763 — Mozilla: Script Execution during invalid object state CVE-2022-22764 — Mozilla: Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2022:0514
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053236
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053238
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053239
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053240
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053242
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053243
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0514.json