Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2020-6831EPSS 6% A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitab… Firefox 68.8.0 / 76.0+ Fix from $2,3002020-05-26 CRITICAL 9.8 CVE-2020-12395 Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence o… Firefox 68.8.0 / 76.0+ Fix from $2,3002020-05-26 CRITICAL 9.8 CVE-2020-12396 Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption a… Firefox 76.0+ Fix from $2,3002020-05-26 CRITICAL 9.8 CVE-2020-6823 A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise return… Firefox 75.0+ Fix from $2,3002020-04-24 CRITICAL 9.8 CVE-2020-6825 Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Som… Firefox 68.7.0 / 75.0+ Fix from $2,3002020-04-24 CRITICAL 9.8 CVE-2020-6826 Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showed evidence… Firefox 75.0+ Fix from $2,3002020-04-24 CRITICAL 9.8 CVE-2020-6814 Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and w… Firefox 68.6.0 / 74.0+ Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2020-6815 Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or es… Firefox 74.0+ Fix from $2,3002020-03-25 CRITICAL 9.3 CVE-2019-9812 Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com … Firefox 60.9 / 68.1+ Fix from $2,3002020-01-08 CRITICAL 9.8 CVE-2019-11733 When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found … Firefox 68.0.2+ Fix from $2,3002019-09-27 CRITICAL 9.8 CVE-2019-11734 Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption a… Firefox 69.0+ Fix from $2,3002019-09-27 CRITICAL 9.8 CVE-2019-9819 A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. Thi… Firefox 60.7 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-9820 A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable c… Firefox 60.7 / 60.7.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-9800 Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bug… Firefox 60.7 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-9814 Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption a… Firefox 67.0+ Fix from $2,3002019-07-23 CRITICAL 10.0 CVE-2019-11708 KEVEPSS 56% Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent … Firefox 60.7.2 / 67.0.4+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11704EPSS 11% A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages,… Thunderbird 60.7.1+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11705EPSS 10% A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, res… Thunderbird 60.7.1+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11709 Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence o… Firefox 60.8.0 / 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11710 Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption a… Firefox 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11713 A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable c… Firefox 60.8.0 / 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11714 Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerabili… Firefox 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11693 The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content f… Firefox 60.7.0 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11703EPSS 11% A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resultin… Thunderbird 60.7.1+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11691 A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it h… Firefox 60.7 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11692 A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially ex… Firefox 60.7.0 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-9804 In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the executio… Firefox 66.0+ Fix from $2,3002019-04-26 CRITICAL 9.8 CVE-2019-9805 A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory co… Firefox 66.0+ Fix from $2,3002019-04-26 CRITICAL 9.8 CVE-2019-9794 A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs… Firefox 60.6.0 / 66.0+ Fix from $2,3002019-04-26 CRITICAL 9.8 CVE-2019-9795 A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a pote… Firefox 60.6 / 66.0+ Fix from $2,3002019-04-26