CVE-2022-29916
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
Affected (3)
Products: Mozilla: Firefox, Firefox Esr, Thunderbird
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 100.0 | |
| Before 91.9 | |
| Before 91.9 |
References (8)
Source: security@mozilla.org
ExploitIssue TrackingVendor Advisory
Source: security@mozilla.org
ExploitVendor Advisory
Source: security@mozilla.org
ExploitVendor Advisory
Source: security@mozilla.org
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Timeline
No history available yet.