Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Firefox CRITICAL 9.8
CVE-2022-31747

Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox …

Fix: 91.10 / 101+
Fix from $2,300 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-28285

When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerabil…

Fix: 91.8 / 99.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22742

When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This …

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2021-29988

Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentiall…

Fix: 78.13.0 / 91.0+
Fix from $1,950 2021-08-17
Firefox HIGH 8.1
CVE-2021-29968

When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operatin…

Fix: 89.0.1+
Fix from $1,950 2021-06-24
Firefox HIGH 7.1
CVE-2021-29964

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This…

Fix: 78.11 / 89.0+
Fix from $1,950 2021-06-24
Nss CRITICAL 9.1
CVE-2020-12403

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-b…

Fix: 3.55+
Fix from $2,300 2021-05-27
Firefox MEDIUM 6.5
CVE-2020-12425

Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information d…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12407

Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible scre…

Fix: 77.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12418

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerabi…

Fix: 68.10 / 68.10.0+
Fix from $1,600 2020-07-09
Firefox HIGH 8.8
CVE-2020-6806

By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. Th…

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Firefox HIGH 7.5
CVE-2019-11719

When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Secur…

Fix: 60.8.0 / 68.0+
Fix from $1,950 2019-07-23
Firefox HIGH 7.5
CVE-2019-9802

If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The d…

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox HIGH 7.5
CVE-2019-9799

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the …

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox CRITICAL 9.1
CVE-2017-7774

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

Fix: 1.3.10 / 54.0+
Fix from $2,300 2019-04-15
Firefox HIGH 8.1
CVE-2017-7771

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Firefox HIGH 8.1
CVE-2017-7776

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Firefox CRITICAL 9.8
CVE-2018-18504

A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This result…

Fix: 65.0+
Fix from $2,300 2019-02-05
Firefox HIGH 7.5
CVE-2018-5153

If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read …

Fix: 60.0+
Fix from $1,950 2018-06-11
Firefox HIGH 8.2
CVE-2017-7813

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually resu…

Fix: after 55.0.3
Fix from $1,950 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7778EPSS 5%

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninit…

Fix: 1.3.10 / 52.2.0+
Fix from $2,300 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5418

An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of ran…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5271

The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds …

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Firefox MEDIUM 6.5
CVE-2016-2827

The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds r…

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Firefox CRITICAL 9.1
CVE-2014-1508

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey befor…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox HIGH 8.8
CVE-2014-1497

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonke…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox HIGH 9.3
CVE-2013-0778

The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attacker…

Fix: 2.16 / 17.0.3+
Fix from $1,950 2013-02-19
Firefox HIGH 9.3
CVE-2013-0779EPSS 5%

The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attac…

Fix: 2.16 / 17.0.3+
Fix from $1,950 2013-02-19
Firefox HIGH 10.0
CVE-2013-0767EPSS 6%

The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird…

Fix: 2.15 / 10.0.12+
Fix from $1,950 2013-01-13
Firefox HIGH 9.3
CVE-2012-3995EPSS 5%

The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x befo…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10