CVE-2022-29914
Mozilla: Fullscreen notification bypass using popups
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
Al reutilizar ventanas emergentes existentes, Firefox les habría permitido cubrir la interfaz de usuario de notificación en pantalla completa, lo que podría haber permitido ataques de suplantación de identidad del navegador. Esta vulnerabilidad afecta a Thunderbird < 91.9, Firefox ESR < 91.9 y Firefox < 100.
A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of when reusing existing popups; Firefox allowed them to cover the fullscreen notification UI, which possibly enabled browser spoofing attacks.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-29 CVE Reserved
- 2022-05-04 CVE Published
- 2024-07-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1021: Improper Restriction of Rendered UI Layers or Frames
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2022-16 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-17 | 2023-01-04 | |
https://www.mozilla.org/security/advisories/mfsa2022-18 | 2023-01-04 | |
https://access.redhat.com/security/cve/CVE-2022-29914 | 2022-05-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2081468 | 2022-05-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mozilla Search vendor "Mozilla" | Firefox Search vendor "Mozilla" for product "Firefox" | < 100.0 Search vendor "Mozilla" for product "Firefox" and version " < 100.0" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Firefox Esr Search vendor "Mozilla" for product "Firefox Esr" | < 91.9 Search vendor "Mozilla" for product "Firefox Esr" and version " < 91.9" | - |
Affected
| ||||||
Mozilla Search vendor "Mozilla" | Thunderbird Search vendor "Mozilla" for product "Thunderbird" | < 91.9 Search vendor "Mozilla" for product "Thunderbird" and version " < 91.9" | - |
Affected
|