Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2024-5699

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked w…

Fix: 127.0+
Fix from $2,300 2024-06-11
Firefox CRITICAL 9.8
CVE-2024-5701

Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 127.0+
Fix from $2,300 2024-06-11
Firefox CRITICAL 9.8
CVE-2024-4778

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 126.0+
Fix from $2,300 2024-05-14
Firefox CRITICAL 9.8
CVE-2024-4764

Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

Fix: 126.0+
Fix from $2,300 2024-05-14
Firefox CRITICAL 9.8
CVE-2024-3863

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other oper…

Fix: 115.10 / 115.10.0+
Fix from $2,300 2024-04-16
Firefox CRITICAL 9.8
CVE-2024-29943EPSS 23%

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerabi…

Fix: 124.0.1+
Fix from $2,300 2024-03-22
Firefox CRITICAL 9.8
CVE-2024-2615

Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 124.0+
Fix from $2,300 2024-03-19
Firefox CRITICAL 9.8
CVE-2024-1554

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Und…

Fix: 123.0+
Fix from $2,300 2024-02-20
Firefox Mobile CRITICAL 9.8
CVE-2023-49060

An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulne…

Fix: 120.0+
Fix from $2,300 2023-11-21
Firefox CRITICAL 9.8
CVE-2023-5730

Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.4 / 115.4.1+
Fix from $2,300 2023-10-25
Firefox CRITICAL 9.8
CVE-2023-5731

Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 119.0+
Fix from $2,300 2023-10-25
Firefox CRITICAL 9.8
CVE-2023-5168

A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially ex…

Fix: 115.3 / 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5172

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitab…

Fix: 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5174

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-af…

Fix: 115.3 / 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5175

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, lead…

Fix: 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5176

Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.3 / 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-4056

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showe…

Fix: 102.14 / 115.1+
Fix from $2,300 2023-08-01
Firefox CRITICAL 9.8
CVE-2023-4057

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.1 / 116.0+
Fix from $2,300 2023-08-01
Firefox CRITICAL 9.8
CVE-2023-4058

Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 116.0+
Fix from $2,300 2023-08-01
Firefox CRITICAL 9.8
CVE-2023-34416

Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we…

Fix: 102.12 / 114.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-34417

Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 114.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 10.0
CVE-2019-25136

A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. T…

Fix: 70.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-25736

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.

Fix: 110.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-29542

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk wi…

Fix: 102.10 / 112.0+
Fix from $2,300 2023-06-19
Firefox Focus CRITICAL 9.1
CVE-2023-29534

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusi…

Fix: 112.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-29531

An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *Th…

Fix: 102.10 / 112.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-32216

Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs prese…

Fix: 113.0+
Fix from $2,300 2023-06-19
Thunderbird CRITICAL 9.8
CVE-2021-43529

Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird ver…

Fix: 91.3.0+
Fix from $2,300 2023-02-16
Firefox CRITICAL 9.8
CVE-2022-46882

A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6…

Fix: 102.6 / 107.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-45406

If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a Base…

Fix: 102.5 / 107.0+
Fix from $2,300 2022-12-22