Mozilla Foundation Security Advisory 2022-31
Security Vulnerabilities fixed in Thunderbird 91.12
- Announced
- July 28, 2022
- Impact
- moderate
- Products
- Thunderbird
- Fixed in
-
- Thunderbird 91.12
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
#CVE-2022-36319: Mouse Position spoofing with CSS transforms
- Reporter
- Irvan Kurniawan
- Impact
- moderate
Description
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed.
References
#CVE-2022-36318: Directory indexes for bundled resources reflected URL parameters
- Reporter
- Gijs Kruitbosch
- Impact
- moderate
Description
When visiting directory listings for chrome://
URLs as source text, some parameters were reflected.