Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Debian Linux HIGH 7.5
CVE-2017-7843

When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB …

Fix: 52.5.2 / 57.0.1+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2017-7844

A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which …

Fix: 57.0.1+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7808

A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the o…

Fix: 55.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7812

If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to …

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-7787

Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top …

Fix: 55.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-7759

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of l…

Fix: 54.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the s…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Enterprise Linux HIGH 7.5
CVE-2017-5454

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file …

Fix: 52.1.0 / 53.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5425

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some da…

Fix: 52.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 6.5
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted us…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-5408

Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potenti…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-5414

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to inform…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5382

Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal inform…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.9
CVE-2017-5384

Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information tha…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5385

Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to po…

Fix: 51.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2016-9904

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This …

Fix: 45.6.0 / 51.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-5378

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash…

Fix: 45.7.0 / 51.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-9074

An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NS…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-5288

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This i…

Fix: 49.0.2+
Fix from $1,600 2018-06-11
Octopus Server HIGH 7.5
CVE-2018-12089

In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabri…

Fix: after 2018.5.7
Fix from $1,950 2018-06-11
Mxnet MEDIUM 6.5
CVE-2018-1281

The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_…

Fix: 1.0.0+
Fix from $1,600 2018-06-08
Iphone Os HIGH 7.5
CVE-2018-4221

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Security" c…

Fix: 10.13.5 / 11.4+
Fix from $1,950 2018-06-08
Apple Tv MEDIUM 5.5
CVE-2018-4223

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watch…

Fix: 4.3.1 / 10.13.5+
Fix from $1,600 2018-06-08
Apple Tv MEDIUM 5.5
CVE-2018-4224

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is aff…

Fix: 4.3.1 / 7.5+
Fix from $1,600 2018-06-08
Iphone Os MEDIUM 5.5
CVE-2018-4226

An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is aff…

Fix: 4.3.1 / 7.5+
Fix from $1,600 2018-06-08
Mac Os X MEDIUM 5.5
CVE-2018-4141

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Intel Graphics Driver" component. It all…

Fix: 10.13.5+
Fix from $1,600 2018-06-08
Mac Os X MEDIUM 5.5
CVE-2018-4159

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Graphics Drivers" component. It allows a…

Fix: 10.13.5+
Fix from $1,600 2018-06-08
Mac Os X MEDIUM 5.5
CVE-2018-4171

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth" component. It allows attacker…

Fix: 10.13.5+
Fix from $1,600 2018-06-08
Mac Os X HIGH 7.8
CVE-2018-4196

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Accessibility Framework" component. It a…

Fix: 10.13.5+
Fix from $1,950 2018-06-08
Crowbar MEDIUM 5.5
CVE-2012-0433

The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allo…

Fix: after 1.0
Fix from $1,600 2018-06-08