Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2018-5169
If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a…
Ubuntu Linux
60.0+
MEDIUM 5.3
CVE-2018-5173
The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be use…
Ubuntu Linux
60.0+
HIGH 8.8
CVE-2018-5130
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. T…
Debian Linux
52.7.0 / 59.0+
HIGH 7.5
CVE-2018-5136
A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vu…
Ubuntu Linux
59.0+
MEDIUM 5.3
CVE-2018-5138
A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel insid…
Firefox
59.0+
HIGH 8.2
CVE-2018-5141
A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction.…
Firefox
59.0+
MEDIUM 5.3
CVE-2018-5110
If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible wi…
Firefox
after 57.0.4
MEDIUM 6.5
CVE-2018-5111
When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site …
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2018-5121
Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an International…
Firefox
after 57.0.4
MEDIUM 5.3
CVE-2017-7825
Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for do…
Debian Linux
52.4.0 / 56.0+
MEDIUM 5.3
CVE-2017-7829
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not d…
Enterprise Linux Aus
52.5.2+
MEDIUM 5.3
CVE-2017-7832
The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7833
Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some fon…
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7837
SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57.
Firefox
after 56.0.2
MEDIUM 5.3
CVE-2017-7838
Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode disp…
Firefox
after 56.0.2
HIGH 8.1
CVE-2017-7807
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed…
Debian Linux
52.3.0 / 55.0+
HIGH 7.8
CVE-2017-7814
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature …
Enterprise Linux Desktop
52.4.0 / 56.0+
MEDIUM 5.3
CVE-2017-7815
On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as th…
Firefox
after 55.0.3
MEDIUM 5.3
CVE-2017-7816
WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavi…
Firefox
after 55.0.3
MEDIUM 5.3
CVE-2017-7817
A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. Th…
Firefox
after 55.0.3
HIGH 7.5
CVE-2017-7783EPSS 14%
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal p…
Firefox
55.0+
MEDIUM 5.3
CVE-2017-7791
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page naviga…
Debian Linux
52.3.0 / 55.0+
HIGH 7.5
CVE-2017-7804
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write a…
Firefox
52.3.0 / 55.0+
HIGH 7.5
CVE-2017-7762
When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing…
Enterprise Linux Desktop
54.0+
MEDIUM 5.3
CVE-2017-7763
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name s…
Firefox
52.2.0 / 54.0+
MEDIUM 5.3
CVE-2017-7764
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rend…
Firefox
52.2.0 / 54.0+
HIGH 7.5
CVE-2017-7765
The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the W…
Firefox
52.2.0 / 54.0+
MEDIUM 5.9
CVE-2017-7770
A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This w…
Firefox
54.0+
MEDIUM 5.3
CVE-2017-5463
Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of …
Firefox
53.0+
HIGH 7.5
CVE-2017-5449
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit…
Enterprise Linux
52.1.0 / 53.0+