Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ubuntu Linux MEDIUM 6.5
CVE-2018-5169

If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a…

Fix: 60.0+
Fix from $1,600 2018-06-11
Ubuntu Linux MEDIUM 5.3
CVE-2018-5173

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be use…

Fix: 60.0+
Fix from $1,600 2018-06-11
Debian Linux HIGH 8.8
CVE-2018-5130

When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. T…

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-5136

A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vu…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5138

A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel insid…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox HIGH 8.2
CVE-2018-5141

A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction.…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5110

If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible wi…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5111

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site …

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5121

Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an International…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-7825

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for do…

Fix: 52.4.0 / 56.0+
Fix from $1,600 2018-06-11
Enterprise Linux Aus MEDIUM 5.3
CVE-2017-7829

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d…

Fix: 52.5.2+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7832

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7833

Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some fon…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7837

SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57.

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7838

Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode disp…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Debian Linux HIGH 8.1
CVE-2017-7807

A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.8
CVE-2017-7814

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature …

Fix: 52.4.0 / 56.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7815

On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as th…

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7816

WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavi…

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7817

A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. Th…

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-7783EPSS 14%

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal p…

Fix: 55.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-7791

On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page naviga…

Fix: 52.3.0 / 55.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-7804

The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write a…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7762

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing…

Fix: 54.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7763

Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name s…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7764

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rend…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-7765

The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the W…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.9
CVE-2017-7770

A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This w…

Fix: 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5463

Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of …

Fix: 53.0+
Fix from $1,600 2018-06-11
Enterprise Linux HIGH 7.5
CVE-2017-5449

A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit…

Fix: 52.1.0 / 53.0+
Fix from $1,950 2018-06-11