Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 6.5 CVE-2018-5169 If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a… Ubuntu Linux 60.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5173 The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be use… Ubuntu Linux 60.0+ Fix from $1,6002018-06-11 HIGH 8.8 CVE-2018-5130 When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. T… Debian Linux 52.7.0 / 59.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5136 A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vu… Ubuntu Linux 59.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2018-5138 A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel insid… Firefox 59.0+ Fix from $1,6002018-06-11 HIGH 8.2 CVE-2018-5141 A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction.… Firefox 59.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2018-5110 If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible wi… Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2018-5111 When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site … Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5121 Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an International… Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7825 Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for do… Debian Linux 52.4.0 / 56.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7829 It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d… Enterprise Linux Aus 52.5.2+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7832 The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7833 Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some fon… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7837 SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57. Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7838 Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode disp… Firefox after 56.0.2 Fix from $1,6002018-06-11 HIGH 8.1 CVE-2017-7807 A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed… Debian Linux 52.3.0 / 55.0+ Fix from $1,9502018-06-11 HIGH 7.8 CVE-2017-7814 File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature … Enterprise Linux Desktop 52.4.0 / 56.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7815 On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as th… Firefox after 55.0.3 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7816 WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavi… Firefox after 55.0.3 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7817 A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. Th… Firefox after 55.0.3 Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-7783EPSS 14% If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal p… Firefox 55.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7791 On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page naviga… Debian Linux 52.3.0 / 55.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-7804 The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write a… Firefox 52.3.0 / 55.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7762 When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing… Enterprise Linux Desktop 54.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7763 Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name s… Firefox 52.2.0 / 54.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7764 Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rend… Firefox 52.2.0 / 54.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-7765 The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the W… Firefox 52.2.0 / 54.0+ Fix from $1,9502018-06-11 MEDIUM 5.9 CVE-2017-7770 A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This w… Firefox 54.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-5463 Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of … Firefox 53.0+ Fix from $1,6002018-06-11 HIGH 7.5 CVE-2017-5449 A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit… Enterprise Linux 52.1.0 / 53.0+ Fix from $1,9502018-06-11