Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Firefox HIGH 7.5
CVE-2017-5450

A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, mak…

Fix: 53.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5417

When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displa…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2017-5420

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker t…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5421

A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is curre…

Fix: 52.0.+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5422

If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the h…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5415EPSS 13%

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furth…

Fix: 52.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-5383

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing…

Fix: 45.7.0 / 51.0+
Fix from $1,600 2018-06-11
Enterprise Linux Aus CRITICAL 9.8
CVE-2016-9901

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa…

Fix: 45.6.0 / 50.1+
Fix from $2,300 2018-06-11
Firefox HIGH 7.5
CVE-2016-9065

The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location …

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-9076

An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e1…

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5291

A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firef…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5292

During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5293

When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local …

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5294

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerabilit…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5298

A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when the new pa…

Fix: 50.0+
Fix from $1,600 2018-06-11
Puppet HIGH 7.8
CVE-2018-6515

Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially craf…

Fix: 1.10.13 / 5.3.7+
Fix from $1,950 2018-06-11
Open Build Service HIGH 7.5
CVE-2011-4181

A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases…

Fix: 2.1.16+
Fix from $1,950 2018-06-11
Lepton MEDIUM 5.5
CVE-2018-12108

An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,600 2018-06-11
Futurxe HIGH 7.5
CVE-2018-12025

The transferFrom function of a smart contract implementation for FuturXE (FXE), an Ethereum ERC20 token, allows attackers to accomplish an unauthoriz…

Mitigation only
Fix from $1,950 2018-06-11
S3ql HIGH 7.5
CVE-2018-12088

S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versio…

Fix: 2.27+
Fix from $1,950 2018-06-10
Iphone Os MEDIUM 6.5
CVE-2018-4240EPSS 7%

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watch…

Fix: 4.3.1 / 10.13.5+
Fix from $1,600 2018-06-08
Safari MEDIUM 6.5
CVE-2018-4247

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. The issue involves the "Safari" com…

Fix: 11.1.1 / 11.4+
Fix from $1,600 2018-06-08
Iphone Os MEDIUM 6.5
CVE-2018-4250

An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Messages" component. It allows remote attacke…

Fix: 11.4+
Fix from $1,600 2018-06-08
Safari MEDIUM 6.5
CVE-2018-4205

An issue was discovered in certain Apple products. Safari before 11.1.1 is affected. The issue involves the "Safari" component. It allows remote atta…

Fix: 11.1.1+
Fix from $1,600 2018-06-08
Iphone Os MEDIUM 5.5
CVE-2018-4225

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is aff…

Fix: 4.3.1 / 7.5+
Fix from $1,600 2018-06-08
Iphone Os MEDIUM 6.5
CVE-2018-4187

An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2018-001 is affected. The issu…

Fix: 10.13.4 / 11.3.1+
Fix from $1,600 2018-06-08
Safari MEDIUM 6.5
CVE-2018-4188

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is aff…

Fix: 7.5 / 11.1.1+
Fix from $1,600 2018-06-08
Apple Tv MEDIUM 5.5
CVE-2018-4198

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watch…

Fix: 4.3.1 / 10.13.5+
Fix from $1,600 2018-06-08
Iphone Os MEDIUM 5.9
CVE-2018-4202

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "iBooks" com…

Fix: 10.13.5 / 11.4+
Fix from $1,600 2018-06-08
Open Build Service CRITICAL 9.8
CVE-2014-0593

The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). In versions prior to 0.5.3-1.1…

Fix: 1.1+
Fix from $2,300 2018-06-08