SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Mozilla Patches High-Risk Vulnerabilities in Firefox and Thunderbird

Mozilla Patches High-Risk Vulnerabilities in Firefox and Thunderbird

Mozilla has released security updates for Firefox, Firefox ESR (CVE-2022-22746), and mailing client Thunderbird. There are 18 vulnerabilities in Firefox,14 vulnerabilities in Firefox ESR, and in Thunderbird 14 vulnerabilities were found and fixed. The advisories for these products have been rated hi...

Jan 16, 2022By Mansij Gupta2 min read

Mozilla has released security updates for Firefox,Firefox ESR (CVE-2022-22746), and mailing client Thunderbird. There are 18 vulnerabilities in Firefox,14 vulnerabilities in Firefox ESR, and in Thunderbird 14 vulnerabilities were found and fixed. The advisories for these products have been rated high severity. Most of these vulnerabilities could lead to Race-Condition, Fullscreen access, out-of-bounds memory access, Use-after-free, heap buffer overflow, Iframe sandbox bypass with XSLT. A vulnerability management tool can prevent such attacks from happening.

Out of the above vulnerabilities, the most severe one is a race condition issue tracked as CVE-2022-22746. The vulnerability only impacts Firefox for Windows operating systems. A race condition could have allowed bypassing the fullscreen notification, which could have lead to a fullscreen window spoof being unnoticed. Another vulnerability is a fullscreen spoof in the Firefox browser window tracked as CVE-2022-22743. The vulnerability can allow an attacker-controlled tab to prevent the browser from leaving fullscreen mode when the user navigates from inside an iframe. One more vulnerability is an out-of-bounds memory access leading to a potentially exploitable crash, and the flaw has been tracked as CVE-2022-22742. Deploying patches will be easier with a patch management tool.

Mozilla Security Updates Summary for January 2022

Product: Mozilla FirefoxAdvisory/CVEs:  MFSA2022-01 ,  CVE-2022-22746 , CVE-2022-22743 , CVE-2022-22742 , CVE-2022-22741 , CVE-2022-22740 , CVE-2022-22738  ,  CVE-2022-22737 , CVE-2021-4140 , CVE-2022-22750 , CVE-2022-22749 , CVE-2022-22748 , CVE-2022-22745 , CVE-2022-22744  ,  CVE-2022-22747  ,  CVE-2022-22736 , CVE-2022-22739 , CVE-2022-22751 , CVE-2022-22752Severity: HighImpact: Race condition, Fullscreen access, Out-of-bounds memory access, Use-after-free, Heap buffer overflow, Iframe sandbox bypass with XSLT.

Product: Mozilla Firefox ESRAdvisory/CVEs: MFSA2022-02 , CVE-2022-22746 , CVE-2022-22743 , CVE-2022-22742 , CVE-2022-22741 , CVE-2022-22740 , CVE-2022-22738 , CVE-2022-22737 , CVE-2021-4140, CVE-2022-22748 , CVE-2022-22745 , CVE-2022-22744 , CVE-2022-22747 , CVE-2022-22739 , CVE-2022-22751Severity: HighImpact: Race condition, Fullscreen access, Out-of-bounds memory access, Use-after-free, Heap buffer overflow, Iframe sandbox bypass with XSLT.

Product: Mozilla ThunderbirdAdvisory/CVEs: MFSA2022-02 , CVE-2022-22746, CVE-2022-22743, CVE-2022-22742, CVE-2022-22741, CVE-2022-22740, CVE-2022-22738, CVE-2022-22737 , CVE-2022-22748, CVE-2022-22745, CVE-2022-22744,CVE-2022-22747,CVE-2022-22739,CVE-2022-22751Severity: HighImpact: Race condition, fullscreen access, Out-of-bounds memory access, Use-after-free, Heap buffer overflow, Iframe sandbox bypass with XSLT.

Affected Products by CVE-2022-22746:

1. Mozilla Firefox below 96.0
2. Mozilla Firefox ESR below 91.5 and
3. Mozilla Thunderbird below 91.5

Solution:

1. Mozilla Firefox 96.0
2. Mozilla Firefox ESR 91.5
3. Mozilla Thunderbird 91.5

SanerNow VM and SanerNow PM detect these vulnerabilities and automatically fix them by applying security updates. Use SanerNow and keep your systems updated and secure.

Featured Posts

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026

Open Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers
Secpod_VEX_Studio For Open-Source Vulnerability Management

CVE Research

Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers

A human-guided path from SBOM and vulnerability data to reviewable OpenVEX statements

Sep 2, 2026

Open Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution
Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

CVE Research

Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

Sep 1, 2026

Mozilla Patches High-Risk Vulnerabilities in Firefox and Thunderbird | SecPod