Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2020-6831EPSS 6%

A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitab…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-12395

Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence o…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-12396

Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption a…

Fix: 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-6823

A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise return…

Fix: 75.0+
Fix from $2,300 2020-04-24
Firefox CRITICAL 9.8
CVE-2020-6825

Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Som…

Fix: 68.7.0 / 75.0+
Fix from $2,300 2020-04-24
Firefox CRITICAL 9.8
CVE-2020-6826

Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showed evidence…

Fix: 75.0+
Fix from $2,300 2020-04-24
Firefox CRITICAL 9.8
CVE-2020-6814

Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and w…

Fix: 68.6.0 / 74.0+
Fix from $2,300 2020-03-25
Firefox CRITICAL 9.8
CVE-2020-6815

Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or es…

Fix: 74.0+
Fix from $2,300 2020-03-25
Firefox CRITICAL 9.3
CVE-2019-9812

Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com …

Fix: 60.9 / 68.1+
Fix from $2,300 2020-01-08
Firefox CRITICAL 9.8
CVE-2019-11733

When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found …

Fix: 68.0.2+
Fix from $2,300 2019-09-27
Firefox CRITICAL 9.8
CVE-2019-11734

Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption a…

Fix: 69.0+
Fix from $2,300 2019-09-27
Firefox CRITICAL 9.8
CVE-2019-9819

A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. Thi…

Fix: 60.7 / 67.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-9820

A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable c…

Fix: 60.7 / 60.7.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-9800

Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bug…

Fix: 60.7 / 67.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-9814

Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption a…

Fix: 67.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 10.0
CVE-2019-11708 KEVEPSS 56%

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent …

Fix: 60.7.2 / 67.0.4+
Fix from $2,300 2019-07-23
Thunderbird CRITICAL 9.8
CVE-2019-11704EPSS 11%

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages,…

Fix: 60.7.1+
Fix from $2,300 2019-07-23
Thunderbird CRITICAL 9.8
CVE-2019-11705EPSS 10%

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, res…

Fix: 60.7.1+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11709

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence o…

Fix: 60.8.0 / 68.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11710

Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption a…

Fix: 68.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11713

A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable c…

Fix: 60.8.0 / 68.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11714

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerabili…

Fix: 68.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11693

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content f…

Fix: 60.7.0 / 67.0+
Fix from $2,300 2019-07-23
Thunderbird CRITICAL 9.8
CVE-2019-11703EPSS 11%

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resultin…

Fix: 60.7.1+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11691

A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it h…

Fix: 60.7 / 67.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11692

A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially ex…

Fix: 60.7.0 / 67.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-9804

In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the executio…

Fix: 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9805

A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory co…

Fix: 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9794

A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9795

A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a pote…

Fix: 60.6 / 66.0+
Fix from $2,300 2019-04-26