Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2018-5184

Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird…

Mitigation only
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5154

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitabl…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5155

A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable cras…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5159EPSS 21%

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 8.8
CVE-2018-5158EPSS 10%

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF fil…

Fix: 52.8.0 / 60.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2018-5168

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could…

Fix: 52.8.0 / 60.0+
Fix from $1,600 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5145

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that som…

Fix: 52.7.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5147

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vu…

Fix: 52.7.2 / 59.0.1+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5148

A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference count…

Fix: 52.7.3 / 59.0.2+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5150

Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and w…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 8.8
CVE-2018-5130

When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. T…

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 8.6
CVE-2018-5129

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow …

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.9
CVE-2018-5131

Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache hea…

Fix: 52.7.0 / 59.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2018-5117

If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the d…

Fix: 52.6.0 / 58.0+
Fix from $1,600 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5091

A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable c…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5095

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This result…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5096

A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerab…

Fix: 52.6.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5097EPSS 7%

A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content …

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5098

A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potenti…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5099

A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, re…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5102EPSS 7%

A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5103

A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitab…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5104EPSS 7%

A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially explo…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7826

Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 52.5.0 / 57.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7828EPSS 7%

A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This re…

Fix: 52.5.0 / 57.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-7843

When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB …

Fix: 52.5.2 / 57.0.1+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 6.5
CVE-2017-7830

The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data the…

Fix: 52.5.0 / 57.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-7825

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for do…

Fix: 52.4.0 / 56.0+
Fix from $1,600 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7809

A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This…

Fix: 52.3.0 / 55.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7810

Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11