Vulnerability index

Browse CVEs

361 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
CRITICAL 9.8 CVE-2007-5341 Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8. Firefox after 2.0.0.7 Fix from $2,3002017-08-18 HIGH 8.8 CVE-2016-5278 Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird … Firefox after 48.0.2 Fix from $1,9502016-09-22 HIGH 8.8 CVE-2016-5275 Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to exe… Firefox after 48.0.2 Fix from $1,9502016-09-22 CRITICAL 9.8 CVE-2016-5270 Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5257 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow … Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5256 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory… Firefox after 48.0.2 Fix from $2,3002016-09-22 HIGH 8.8 CVE-2016-2838 Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows rem… Firefox after 47.0.1 Fix from $1,9502016-08-05 MEDIUM 6.3 CVE-2016-2837 Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0… Firefox after 47.0.1 Fix from $1,6002016-08-05 HIGH 8.8 CVE-2016-2836 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to … Firefox after 47.0.1 Fix from $1,9502016-08-05 HIGH 8.8 CVE-2016-2824 The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to … Firefox after 46.0.1 Fix from $1,9502016-06-13 HIGH 8.8 CVE-2016-2819EPSS 24% Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via fore… Firefox after 46.0.1 Fix from $1,9502016-06-13 HIGH 8.8 CVE-2016-2818 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to … Firefox after 46.0.1 Fix from $1,9502016-06-13 HIGH 8.8 CVE-2016-2815 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory… Firefox after 46.0.1 Fix from $1,9502016-06-13 CRITICAL 9.8 CVE-2016-0718EPSS 13% Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, whic… Firefox 2.7.15 / 3.3.7+ Fix from $2,3002016-05-26 HIGH 8.8 CVE-2016-2814 Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ES… Firefox after 45.0.2 Fix from $1,9502016-04-30 HIGH 7.5 CVE-2016-2808 The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allo… Firefox after 45.0.2 Fix from $1,9502016-04-30 HIGH 8.8 CVE-2016-2807 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before … Firefox after 45.0.2 Fix from $1,9502016-04-30 HIGH 8.8 CVE-2016-2805 Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory … Firefox Mitigation only Fix from $1,9502016-04-30 HIGH 8.8 CVE-2016-2804 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory… Firefox after 45.0.2 Fix from $1,9502016-04-30 HIGH 8.8 CVE-2016-2802 The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x b… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2800 The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2798 The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2794 The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x … Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2792 The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2791 The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1974 The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation … Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1971 The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, wh… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1970 Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers … Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1969 The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers t… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 7.4 CVE-2016-1963 The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changin… Firefox after 44.0.2 Fix from $1,9502016-03-13