Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Firefox HIGH 7.5
CVE-2026-12314

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16
Firefox HIGH 7.5
CVE-2026-12310

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0.0+
Fix from $1,950 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12298

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0+
Fix from $1,600 2026-06-16
Firefox HIGH 8.1
CVE-2026-8092

Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed evidence of memory corruption…

Fix: 115.35.2 / 140.10.2+
Fix from $1,950 2026-05-07
Firefox HIGH 7.5
CVE-2026-7320

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ES…

Fix: 115.35.1 / 140.10.1+
Fix from $1,950 2026-04-28
Firefox HIGH 7.5
CVE-2026-6785

Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showe…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-26
Firefox HIGH 7.5
CVE-2026-6786

Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-26
Firefox HIGH 7.5
CVE-2026-6784

Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 150.0+
Fix from $1,950 2026-04-21
Firefox CRITICAL 9.8
CVE-2026-5735

Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that wi…

Fix: 149.0.2+
Fix from $2,300 2026-04-07
Firefox CRITICAL 9.8
CVE-2026-2771

Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox HIGH 8.8
CVE-2025-11714

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showe…

Fix: 115.29.0 / 140.4.0+
Fix from $1,950 2025-10-14
Firefox CRITICAL 9.8
CVE-2025-4918EPSS 9%

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Fir…

Fix: 115.23.1 / 128.10.1+
Fix from $2,300 2025-05-17
Firefox HIGH 8.8
CVE-2025-4919EPSS 9%

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in…

Fix: 115.23.1 / 128.10.1+
Fix from $1,950 2025-05-17
Firefox MEDIUM 5.9
CVE-2025-4082

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used t…

Fix: 115.23 / 128.10+
Fix from $1,600 2025-04-29
Firefox HIGH 8.1
CVE-2025-1932

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and la…

Fix: 128.8.0 / 136.0+
Fix from $1,950 2025-03-04
Firefox HIGH 8.8
CVE-2024-10467

Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we p…

Fix: 128.4.0 / 132.0+
Fix from $1,950 2024-10-29
Firefox MEDIUM 6.5
CVE-2024-10464

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by int…

Fix: 128.4.0 / 132.0+
Fix from $1,600 2024-10-29
Firefox HIGH 8.8
CVE-2024-7522

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR <…

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.2
CVE-2024-6606

Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 a…

Fix: 128.0+
Fix from $1,950 2024-07-09
Firefox HIGH 8.8
CVE-2024-3854

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox…

Fix: 115.10 / 125.0+
Fix from $1,950 2024-04-16
Firefox MEDIUM 6.5
CVE-2024-3855

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

Fix: 125.0+
Fix from $1,600 2024-04-16
Firefox MEDIUM 5.9
CVE-2024-3859

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. T…

Fix: 115.10 / 125.0+
Fix from $1,600 2024-04-16
Firefox CRITICAL 9.8
CVE-2024-29943EPSS 23%

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerabi…

Fix: 124.0.1+
Fix from $2,300 2024-03-22
Firefox HIGH 7.5
CVE-2024-1546

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. …

Fix: 115.8.0 / 123.0+
Fix from $1,950 2024-02-20
Firefox MEDIUM 6.5
CVE-2023-6204

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images cr…

Fix: 115.5 / 115.5.0+
Fix from $1,600 2023-11-21
Firefox HIGH 7.5
CVE-2023-4048

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Fi…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Firefox MEDIUM 6.5
CVE-2023-32206

An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunder…

Fix: 102.11 / 113.0+
Fix from $1,600 2023-06-02
Firefox MEDIUM 6.5
CVE-2023-25738

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which …

Fix: 102.8 / 110.0+
Fix from $1,600 2023-06-02
Firefox HIGH 8.6
CVE-2022-46872

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br…

Fix: 102.6 / 108.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 5.5
CVE-2022-3266

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 1…

Fix: 102.3 / 105.0+
Fix from $1,600 2022-12-22