CVE-2022-29914: Medium severity thunderbird vulnerability
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks.
Other sources
When reusing existing popups Thunderbird would allow them to cover the fullscreen notification UI, which could enable browser spoofing attacks.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-29914?
CVE-2022-29914 has a severity rating that allows for browser spoofing attacks by covering the fullscreen notification UI.
How do I fix CVE-2022-29914?
To fix CVE-2022-29914, update your Firefox, Firefox ESR, or Thunderbird to versions 91.9 or 100 as applicable.
Which software is affected by CVE-2022-29914?
CVE-2022-29914 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions prior to 91.9 or 100.
What type of attack does CVE-2022-29914 enable?
CVE-2022-29914 enables browser spoofing attacks by allowing popups to obscure important user interface elements.
When was CVE-2022-29914 disclosed?
CVE-2022-29914 was publicly disclosed in 2022, leading to the issuance of security advisories by Mozilla.