CVE-2022-26381 An attacker could exploit a use-after-free to crash the browser.
A user could enter an unsafe URL in a text field, press enter, and cause a use-after-free resulting in a potentially exploitable crash.
CVE-2022-29912 Requests initiated through reader mode did not properly omit cookies with a SameSite attribute
If a user had a malicious site set as their preferred email provider through an add-on like Preference synchronizer, and then installed an add-
CVE-2022-29915 The Performance API did not properly hide the fact whether a request has observed redirects. This issue is resolved.
This issue has been fixed in Firefox version 101.
In Firefox 101, the Performance API incorrectly returned false when the user navigated from an origin
CVE-2022-41800 An Administrator user can bypass appliance mode restrictions with an undisclosed iControl REST endpoint.
While running in VE, an attacker may be able to access iControl REST endpoints with an unauthenticated user, bypassing VE restrictions. Exploits of VE, like
CVE-2022-30122 - How a Quiet Rack Vulnerability Could Take Down Your Ruby App
If you run Rails or Sinatra apps, it’s very likely you’ve relied on Rack—the foundation for most Ruby web applications. In 2022,
Episode
00:00:00
00:00:00