
CVE-2022-26382 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-26382
10 Aug 2022 — While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98. Si bien JavaScript no puede leer directamente el texto que se muestra en la información sobre herramientas de Autocompletar, el texto se representó utilizando fuentes de página. Los ataques de canal lateral al texto medi... • https://bugzilla.mozilla.org/show_bug.cgi?id=1741888 • CWE-203: Observable Discrepancy •

CVE-2022-34469 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-34469
10 Aug 2022 — When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. On Firefox for Android, the user was presented with the option to bypass the error; this could only have been done by the user explicitly. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102. • https://bugzilla.mozilla.org/show_bug.cgi?id=1721220 • CWE-295: Improper Certificate Validation •

CVE-2022-29910 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-29910
10 Aug 2022 — When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 100. Cuando se cerraba o se enviaba a segundo plano, Firefox para Android no registraba ni conservaba correctamente la configuración HSTS. • https://bugzilla.mozilla.org/show_bug.cgi?id=1757138 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2022-31745 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-31745
10 Aug 2022 — If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101. Si no se utilizan operaciones de cambio de matriz, es posible que el recolector de basura se haya confundido acerca de los objetos válidos. Esta vulnerabilidad afecta a Firefox < 101. Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code. • https://bugzilla.mozilla.org/show_bug.cgi?id=1760944 • CWE-129: Improper Validation of Array Index •

CVE-2022-34476 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-34476
10 Aug 2022 — ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102. El análisis ASN.1 de una SECUENCIA indefinida dentro de un GRUPO indefinido podría haber dado como resultado que el analizador aceptara ASN.1 con formato incorrecto. Esta vulnerabilidad afecta a Firefox < 102. Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code. • https://bugzilla.mozilla.org/show_bug.cgi?id=1387919 • CWE-20: Improper Input Validation •

CVE-2022-34478 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-34478
10 Aug 2022 — The ms-msdt
, search
, and search-ms
protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.
*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnera... • https://bugzilla.mozilla.org/show_bug.cgi?id=1773717 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2022-26385 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-26385
10 Aug 2022 — In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 98. En circunstancias inusuales, un subproceso individual puede sobrevivir al administrador del subproceso durante el cierre. Esto podría haber llevado a un use-after-free que provocó un bloqueo potencialmente explotable. • https://bugzilla.mozilla.org/show_bug.cgi?id=1747526 • CWE-416: Use After Free •

CVE-2022-34471 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-34471
10 Aug 2022 — When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102. Al descargar una actualización para un complemento, no se verificó que la versión de la actualización del complemento descargada coincidiera con la versión seleccionada en el manifiesto. S... • https://bugzilla.mozilla.org/show_bug.cgi?id=1766047 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2022-34474 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-34474
10 Aug 2022 — Even when an iframe was sandboxed with allow-top-navigation-by-user-activation
, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102. Incluso cuando un iframe estaba protegido con allow-top-navigation-by-user-activation
, si recibía un encabezado de redireccionamiento a un protocolo externo, el navegador procesaría el redireccionamiento y avisaría al usuario según ... • https://bugzilla.mozilla.org/show_bug.cgi?id=1677138 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2022-36316 – Gentoo Linux Security Advisory 202208-08
https://notcve.org/view.php?id=CVE-2022-36316
10 Aug 2022 — When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103. Al utilizar la API Performance, un atacante pudo notar diferencias sutiles entre PerformanceEntries y así saber si la URL de destino había sido objeto de una redirección. Esta vulnerabilidad afecta a Firefox < 103. Multiple vulnerabilities have been found in Mozilla Firefox, the worst of... • https://bugzilla.mozilla.org/show_bug.cgi?id=1768583 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •