Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2022-36320

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corr…

Fix: 103.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-34485

Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs sh…

Mitigation only
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-34476

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability af…

Fix: 102.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-34470

Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR…

Fix: 91.11 / 102.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31747

Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox …

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31748

Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in …

Fix: 101+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31737

A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnera…

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-31736

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91…

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-29917

Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and F…

Fix: 91.9 / 100.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.6
CVE-2022-26486 KEV

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in th…

Fix: 91.6.1 / 91.6.2+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.6
CVE-2022-26384

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to…

Fix: 91.7 / 98.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.6
CVE-2022-22759

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. …

Fix: 91.6 / 97.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-1887

The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.

Fix: 101+
Fix from $2,300 2022-12-22
Firefox CRITICAL 10.0
CVE-2021-4140

It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Fire…

Fix: 91.5 / 96.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2021-4129

Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported m…

Fix: 91.4.0 / 95.0+
Fix from $2,300 2022-12-22
Firefox Esr CRITICAL 9.8
CVE-2021-4127

An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird …

Fix: 78.9.0+
Fix from $2,300 2022-12-22
Convict CRITICAL 9.8
CVE-2022-21190

This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-JS-CONVICT-2340604). The [fix]…

Fix: 6.2.3+
Fix from $2,300 2022-05-13
Convict CRITICAL 9.8
CVE-2022-22143

The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** Thi…

Fix: 6.2.2+
Fix from $2,300 2022-05-01
Nss CRITICAL 9.8
CVE-2021-43527EPSS 18%

NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signa…

Fix: 3.68.1 / 3.73+
Fix from $2,300 2021-12-08
Firefox CRITICAL 10.0
CVE-2021-38503

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navig…

Fix: 91.3 / 94.0+
Fix from $2,300 2021-12-08
Firefox CRITICAL 9.8
CVE-2021-29971

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would b…

Fix: 90.0+
Fix from $2,300 2021-08-05
Mozilla Vpn CRITICAL 9.8
CVE-2021-29978

Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit. This vuln…

Fix: 2.3+
Fix from $2,300 2021-08-05
Hubs Cloud Reticulum CRITICAL 9.8
CVE-2021-29954

Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability af…

Fix: 1.0.1+
Fix from $2,300 2021-06-24
Nss CRITICAL 9.1
CVE-2020-12403

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-b…

Fix: 3.55+
Fix from $2,300 2021-05-27
Firefox CRITICAL 9.8
CVE-2020-26972

The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a d…

Fix: 84.0+
Fix from $2,300 2021-01-07
Firefox CRITICAL 9.8
CVE-2020-15683

Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence o…

Fix: 78.4 / 82.0+
Fix from $2,300 2020-10-22
Firefox CRITICAL 9.8
CVE-2020-15684

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 82.0+
Fix from $2,300 2020-10-22
Firefox CRITICAL 10.0
CVE-2020-12388

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 10.0
CVE-2020-12389

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-12390

Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

Fix: 76.0+
Fix from $2,300 2020-05-26