Vulnerability index

Browse CVEs

363 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Firefox MEDIUM 5.0
CVE-2014-1565

The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and T…

Fix: after 31.1.0
Fix from $1,600 2014-09-03
Firefox HIGH 9.3
CVE-2014-1549EPSS 6%

The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not prope…

Fix: after 30.0
Fix from $1,950 2014-07-23
Firefox HIGH 7.5
CVE-2014-1543

Multiple heap-based buffer overflows in the navigator.getGamepads function in the Gamepad API in Mozilla Firefox before 30.0 allow remote attackers t…

Fix: after 29.0.1
Fix from $1,950 2014-06-11
Firefox MEDIUM 6.8
CVE-2014-1542EPSS 5%

Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code vi…

Fix: after 29.0.1
Fix from $1,600 2014-06-11
Firefox HIGH 10.0
CVE-2014-1534EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0 allow remote attackers to cause a denial of service (memory…

Fix: after 29.0.1
Fix from $1,950 2014-06-11
Firefox CRITICAL 9.8
CVE-2014-1493EPSS 8%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox HIGH 10.0
CVE-2013-5602EPSS 5%

The Worker::SetEventListener function in the Web workers implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x befo…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 9.3
CVE-2013-5604EPSS 6%

The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox MEDIUM 6.8
CVE-2013-5596

The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before …

Fix: after 24.0.1
Fix from $1,600 2013-10-30
Firefox HIGH 10.0
CVE-2013-1719EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow r…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 10.0
CVE-2013-1736EPSS 5%

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1721

Integer overflow in the drawLineLoop function in the libGLESv2 library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox bef…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1732EPSS 9%

Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, …

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1720

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonk…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1725

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1730

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox HIGH 10.0
CVE-2013-1718EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, T…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 10.0
CVE-2013-1705

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote at…

Fix: after 22.0
Fix from $1,950 2013-08-07
Firefox HIGH 7.2
CVE-2013-1706

Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0…

Fix: after 22.0
Fix from $1,950 2013-08-07
Firefox HIGH 7.2
CVE-2013-1707

Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunder…

Fix: after 22.0
Fix from $1,950 2013-08-07
Firefox HIGH 8.8
CVE-2013-1690 KEVEPSS 69%

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle…

Fix: 17.0.7 / 22.0+
Fix from $1,950 2013-06-26
Firefox HIGH 10.0
CVE-2013-1676EPSS 6%

The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunder…

Fix: after 20.0.1
Fix from $1,950 2013-05-16
Firefox HIGH 10.0
CVE-2013-1678EPSS 6%

The _cairo_xlib_surface_add_glyph function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird…

Fix: after 20.0.1
Fix from $1,950 2013-05-16
Firefox HIGH 10.0
CVE-2013-1680EPSS 6%

Use-after-free vulnerability in the nsFrameList::FirstChild function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird befo…

Fix: after 20.0.1
Fix from $1,950 2013-05-16
Firefox HIGH 7.2
CVE-2013-0799

Buffer overflow in the Mozilla Maintenance Service in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, and Thu…

Fix: after 19.0.2
Fix from $1,950 2013-04-03
Firefox MEDIUM 5.0
CVE-2013-0791EPSS 5%

The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.…

Fix: 3.15 / 17.0.5+
Fix from $1,600 2013-04-03
Firefox MEDIUM 5.8
CVE-2013-0772

The RasterImage::DrawFrameTo function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attackers to…

Fix: 2.16 / 19.0+
Fix from $1,600 2013-02-19
Firefox HIGH 9.3
CVE-2013-0752EPSS 7%

Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15…

Fix: 2.15 / 17.0.2+
Fix from $1,950 2013-01-13
Firefox HIGH 9.3
CVE-2012-5833

The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunde…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-5838EPSS 6%

The copyTexImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows re…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21