Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.1
CVE-2017-5447EPSS 17%

An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an at…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 8.6
CVE-2017-5448

An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Ge…

Fix: 45.9.0 / 52.1.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-5444EPSS 7%

A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This…

Fix: 45.9.0 / 53.0+
Fix from $1,950 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-5445

A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow…

Fix: 45.9.0 / 53.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5432

A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Th…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5433

A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation cont…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5435

A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially expl…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5438

A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a pote…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5439

A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. T…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5440

A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leadin…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 8.8
CVE-2017-5436

An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash.…

Fix: 45.9.0 / 53.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5401

A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitabl…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5402

A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. T…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5404EPSS 17%

A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5410

Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is mana…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Debian Linux MEDIUM 6.5
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted us…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-5405

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firef…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-5408

Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potenti…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5380

A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR <…

Fix: 45.7.0 / 51.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5390

The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, all…

Fix: 45.7.0 / 51.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5396

A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from …

Fix: 45.7.0 / 51.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5398

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort …

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 7.3
CVE-2017-5386

WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data discl…

Fix: 45.7.0 / 51.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.3
CVE-2017-5383

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing…

Fix: 45.7.0 / 51.0+
Fix from $1,600 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2016-9898

Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Fi…

Fix: 45.6.0 / 50.1.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2016-9899EPSS 21%

Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects F…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5376

Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Fix: 45.7.0 / 51.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 7.5
CVE-2016-9900EPSS 10%

External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allo…

Fix: 45.6.0 / 50.1+
Fix from $1,950 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-5378

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash…

Fix: 45.7.0 / 51.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2016-9893

Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort …

Fix: 45.6.0 / 50.1+
Fix from $2,300 2018-06-11