Mozilla Foundation Security Advisory 2022-29
Security Vulnerabilities fixed in Firefox ESR 91.12
- Announced
- July 26, 2022
- Impact
- moderate
- Products
- Firefox ESR
- Fixed in
-
- Firefox ESR 91.12
#CVE-2022-36319: Mouse Position spoofing with CSS transforms
- Reporter
- Irvan Kurniawan
- Impact
- moderate
Description
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed.
References
#CVE-2022-36318: Directory indexes for bundled resources reflected URL parameters
- Reporter
- Gijs Kruitbosch
- Impact
- moderate
Description
When visiting directory listings for chrome://
URLs as source text, some parameters were reflected.