Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2016-5277

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5276

Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x b…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5274

Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thun…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5270

Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5257

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow …

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5256

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5254

Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attack…

Fix: after 47.0.1
Fix from $2,300 2016-08-05
Firefox CRITICAL 9.8
CVE-2016-0718EPSS 13%

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, whic…

Fix: 2.7.15 / 3.3.7+
Fix from $2,300 2016-05-26
Firefox CRITICAL 9.8
CVE-2016-1962EPSS 6%

Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 al…

Fix: after 44.0.2
Fix from $2,300 2016-03-13
Firefox CRITICAL 9.8
CVE-2016-1946

The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operatio…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox CRITICAL 9.8
CVE-2016-1944

The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of servic…

No fix yet
Fix from $2,300 2016-01-31
Firefox CRITICAL 10.0
CVE-2016-1931EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox CRITICAL 9.8
CVE-2016-1930EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to …

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox CRITICAL 9.8
CVE-2015-7182EPSS 9%

Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firef…

Fix: after 41.0.2
Fix from $2,300 2015-11-05
Firefox CRITICAL 9.8
CVE-2014-1532

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x…

Fix: 24.5 / 29.0+
Fix from $2,300 2014-04-30
Firefox CRITICAL 9.8
CVE-2014-1524EPSS 8%

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonk…

Fix: 24.5 / 29.0+
Fix from $2,300 2014-04-30
Firefox CRITICAL 9.8
CVE-2014-1493EPSS 8%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1510EPSS 82%

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows re…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1511EPSS 84%

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the po…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1514EPSS 6%

vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not vali…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.1
CVE-2014-1508

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey befor…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1477EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and…

Fix: 24.3 / 27.0+
Fix from $2,300 2014-02-06
Firefox CRITICAL 9.8
CVE-2014-1486EPSS 7%

Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, a…

Fix: 24.3 / 27.0+
Fix from $2,300 2014-02-06
Firefox CRITICAL 9.8
CVE-2013-5618EPSS 10%

Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox …

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-6671EPSS 11%

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5613EPSS 9%

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderb…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5615

The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does n…

Fix: 2.23 / 24.2+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5616EPSS 7%

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2,…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5609EPSS 8%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2010-3765 KEVEPSS 83%

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.1…

Mitigation only
Fix from $2,300 2010-10-28