ZeroHour

CVE-2022-29916

PoC ×4
CVSS 3.1
6.5 medium
EPSS
<1%p52
Published
()
Modified
Description

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

Vendors
mozilla
Products
firefox, firefox esr, thunderbird
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.