Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2017-7811

Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 56.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7821

A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific…

Fix: after 55.0.3
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7788

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S…

Fix: 55.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7756

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially e…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7757

A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7778

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninit…

Fix: 1.3.10 / 52.2.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7780

Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 55.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5471

Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.1
CVE-2017-5468

An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash …

Fix: 53.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5403

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after…

Fix: 52.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5413

A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Fix: 52.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5391

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found…

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5392

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruptio…

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5397

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for t…

Fix: 51.0.3+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5399

Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 52.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5373

Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that wi…

Fix: 45.7.0 / 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5374

Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that…

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5377

A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This …

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-9075

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This…

Fix: 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-9080

Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort th…

Fix: 50.1+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5287

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefo…

Fix: 49.0.2+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5289

Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5290

Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 45.5.0 / 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5297

An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affect…

Fix: 45.5.0 / 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-9063EPSS 5%

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Fix: 2.7.15 / 3.3.7+
Fix from $2,300 2018-06-11
Bleach CRITICAL 9.8
CVE-2018-7753

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character en…

Patch available
Fix from $2,300 2018-03-07
Firefox CRITICAL 9.8
CVE-2007-5341

Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.

Fix: after 2.0.0.7
Fix from $2,300 2017-08-18
Network Security Services CRITICAL 9.8
CVE-2017-5461

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows rem…

Fix: 3.21.4 / 3.28.4+
Fix from $2,300 2017-05-11
Firefox CRITICAL 9.8
CVE-2016-5281

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows re…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5280

Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 4…

Fix: after 48.0.2
Fix from $2,300 2016-09-22