Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2025-49710

An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.

Fix: 139.0.4+
Fix from $2,300 2025-06-11
Firefox CRITICAL 9.8
CVE-2025-49709

Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

Fix: 139.0.4+
Fix from $2,300 2025-06-11
Firefox CRITICAL 9.8
CVE-2025-4918EPSS 9%

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Fir…

Fix: 115.23.1 / 128.10.1+
Fix from $2,300 2025-05-17
Firefox CRITICAL 9.1
CVE-2025-4083

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-…

Fix: 115.23 / 128.10+
Fix from $2,300 2025-04-29
Firefox CRITICAL 10.0
CVE-2025-2857

Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised ch…

Fix: 115.21.1 / 128.8.1+
Fix from $2,300 2025-03-27
Firefox CRITICAL 9.8
CVE-2025-1942

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vuln…

Fix: 136.0+
Fix from $2,300 2025-03-04
Firefox CRITICAL 9.1
CVE-2025-1941

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE…

Fix: 136.0+
Fix from $2,300 2025-03-04
Firefox CRITICAL 9.8
CVE-2025-1016

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of…

Fix: 115.20.0 / 128.7.0+
Fix from $2,300 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-1017

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory co…

Fix: 128.7.0 / 135.0+
Fix from $2,300 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-1020

Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 135.0+
Fix from $2,300 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-1009

An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability was fixed in Fir…

Fix: 115.20.0 / 128.7.0+
Fix from $2,300 2025-02-04
Firefox CRITICAL 9.8
CVE-2025-0247EPSS 9%

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 134.0+
Fix from $2,300 2025-01-07
Firefox CRITICAL 9.8
CVE-2024-11698

A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was op…

Fix: 128.5.0 / 133.0+
Fix from $2,300 2024-11-26
Firefox CRITICAL 9.8
CVE-2024-11704

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symme…

Fix: 128.7.0 / 133.0+
Fix from $2,300 2024-11-26
Firefox CRITICAL 9.1
CVE-2024-11705

`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred…

Fix: 133.0+
Fix from $2,300 2024-11-26
Firefox CRITICAL 9.8
CVE-2024-11693

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other …

Fix: 128.5.0 / 133.0+
Fix from $2,300 2024-11-26
Firefox CRITICAL 9.1
CVE-2024-10004

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padloc…

Fix: 131.2.0+
Fix from $2,300 2024-10-15
Firefox CRITICAL 9.8
CVE-2024-9680 KEVEPSS 23%

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t…

Fix: 115.16.0 / 115.16.1+
Fix from $2,300 2024-10-09
Firefox CRITICAL 9.8
CVE-2024-9401

Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory…

Fix: 115.16.0 / 128.3.0+
Fix from $2,300 2024-10-01
Firefox CRITICAL 9.8
CVE-2024-9402

Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we p…

Fix: 128.3.0 / 131.0+
Fix from $2,300 2024-10-01
Firefox CRITICAL 9.8
CVE-2024-9392

A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox E…

Fix: 115.6.0 / 128.3.0+
Fix from $2,300 2024-10-01
Firefox CRITICAL 9.8
CVE-2024-8389

Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Mitigation only
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8381

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This v…

Fix: 115.15 / 128.2+
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8384

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. Thi…

Fix: 115.15 / 128.2+
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8385

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulner…

Fix: 128.2 / 130.0+
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8387

Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we p…

Mitigation only
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.6
CVE-2024-7519

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a s…

Fix: 115.14.0 / 129.0+
Fix from $2,300 2024-08-06
Firefox CRITICAL 9.8
CVE-2024-6611

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderb…

Fix: 128.0+
Fix from $2,300 2024-07-09
Firefox CRITICAL 9.8
CVE-2024-6602

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thu…

Fix: 115.13 / 128.0+
Fix from $2,300 2024-07-09
Firefox CRITICAL 9.8
CVE-2024-5695

If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered,…

Fix: 127.0+
Fix from $2,300 2024-06-11