Vulnerability index

Browse CVEs

361 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Firefox CRITICAL 9.8
CVE-2007-5341

Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.

Fix: after 2.0.0.7
Fix from $2,300 2017-08-18
Firefox HIGH 8.8
CVE-2016-5278

Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird …

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 8.8
CVE-2016-5275

Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to exe…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5270

Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5257

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow …

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5256

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox HIGH 8.8
CVE-2016-2838

Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows rem…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox MEDIUM 6.3
CVE-2016-2837

Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 8.8
CVE-2016-2836

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to …

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-2824

The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to …

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2819EPSS 24%

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via fore…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2818

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to …

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2815

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox CRITICAL 9.8
CVE-2016-0718EPSS 13%

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, whic…

Fix: 2.7.15 / 3.3.7+
Fix from $2,300 2016-05-26
Firefox HIGH 8.8
CVE-2016-2814

Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ES…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 7.5
CVE-2016-2808

The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allo…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2807

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before …

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2805

Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory …

Mitigation only
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2804

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2802

The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x b…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2800

The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2798

The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2794

The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2792

The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2791

The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1974

The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1971

The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, wh…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1970

Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1969

The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers t…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 7.4
CVE-2016-1963

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changin…

Fix: after 44.0.2
Fix from $1,950 2016-03-13