Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-36314


When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.


Published

2022-12-22T20:15:34.807

Last Modified

2025-04-15T18:15:43.207

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-427
  • Type: Secondary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mozilla firefox < 103.0 Yes
Application mozilla firefox_esr < 102.1 Yes
Application mozilla thunderbird < 102.1 Yes
Operating System microsoft windows - No

References