Vulnerability index

Browse CVEs

392 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-7811 Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 56.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7821 A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific… Firefox after 55.0.3 Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7788 When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S… Firefox 55.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7756 A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially e… Firefox 52.2.0 / 54.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7757 A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results… Firefox 52.2.0 / 54.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7778 A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninit… Firefox 1.3.10 / 52.2.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7780 Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 55.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5471 Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 54.0+ Fix from $2,3002018-06-11 CRITICAL 9.1 CVE-2017-5468 An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash … Firefox 53.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5403 When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after… Firefox 52.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5413 A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52. Firefox 52.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5391 Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found… Firefox 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5392 Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruptio… Firefox 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5397 The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for t… Firefox 51.0.3+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5399 Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 52.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5373 Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that wi… Firefox 45.7.0 / 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5374 Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that… Firefox 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5377 A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This … Firefox 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-9075 An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This… Firefox 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-9080 Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort th… Firefox 50.1+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5287 A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefo… Firefox 49.0.2+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5289 Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5290 Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with… Firefox 45.5.0 / 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5297 An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affect… Firefox 45.5.0 / 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-9063EPSS 5% An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50. Firefox 2.7.15 / 3.3.7+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-7753 An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character en… Bleach Patch available Fix from $2,3002018-03-07 CRITICAL 9.8 CVE-2007-5341 Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8. Firefox after 2.0.0.7 Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2017-5461 Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows rem… Network Security Services 3.21.4 / 3.28.4+ Fix from $2,3002017-05-11 CRITICAL 9.8 CVE-2016-5281 Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows re… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5280 Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 4… Firefox after 48.0.2 Fix from $2,3002016-09-22