Vulnerability index

Browse CVEs

60 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
CRITICAL 9.8 CVE-2022-31747 Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox … Firefox 91.10 / 101+ Fix from $2,3002022-12-22 MEDIUM 6.5 CVE-2022-28285 When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerabil… Firefox 91.8 / 99.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-22742 When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This … Firefox 91.5 / 96.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2021-29988 Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentiall… Firefox 78.13.0 / 91.0+ Fix from $1,9502021-08-17 HIGH 8.1 CVE-2021-29968 When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operatin… Firefox 89.0.1+ Fix from $1,9502021-06-24 HIGH 7.1 CVE-2021-29964 A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This… Firefox 78.11 / 89.0+ Fix from $1,9502021-06-24 CRITICAL 9.1 CVE-2020-12403 A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-b… Nss 3.55+ Fix from $2,3002021-05-27 MEDIUM 6.5 CVE-2020-12425 Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information d… Firefox 78.0+ Fix from $1,6002020-07-09 MEDIUM 6.5 CVE-2020-12407 Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible scre… Firefox 77.0+ Fix from $1,6002020-07-09 MEDIUM 6.5 CVE-2020-12418 Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerabi… Firefox 68.10 / 68.10.0+ Fix from $1,6002020-07-09 HIGH 8.8 CVE-2020-6806 By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. Th… Firefox 68.6.0 / 74.0+ Fix from $1,9502020-03-25 HIGH 7.5 CVE-2019-11719 When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Secur… Firefox 60.8.0 / 68.0+ Fix from $1,9502019-07-23 HIGH 7.5 CVE-2019-9802 If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The d… Firefox 66.0+ Fix from $1,9502019-04-26 HIGH 7.5 CVE-2019-9799 Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the … Firefox 66.0+ Fix from $1,9502019-04-26 CRITICAL 9.1 CVE-2017-7774 Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. Firefox 1.3.10 / 54.0+ Fix from $2,3002019-04-15 HIGH 8.1 CVE-2017-7771 Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. Firefox 1.3.10 / 54.0+ Fix from $1,9502019-04-15 HIGH 8.1 CVE-2017-7776 Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. Firefox 1.3.10 / 54.0+ Fix from $1,9502019-04-15 CRITICAL 9.8 CVE-2018-18504 A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This result… Firefox 65.0+ Fix from $2,3002019-02-05 HIGH 7.5 CVE-2018-5153 If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read … Firefox 60.0+ Fix from $1,9502018-06-11 HIGH 8.2 CVE-2017-7813 Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually resu… Firefox after 55.0.3 Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2017-7778EPSS 5% A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninit… Firefox 1.3.10 / 52.2.0+ Fix from $2,3002018-06-11 MEDIUM 5.3 CVE-2017-5418 An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of ran… Firefox 52.0+ Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2016-5271 The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds … Firefox after 48.0.2 Fix from $1,6002016-09-22 MEDIUM 6.5 CVE-2016-2827 The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds r… Firefox after 48.0.2 Fix from $1,6002016-09-22 CRITICAL 9.1 CVE-2014-1508 The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey befor… Firefox 24.4 / 28.0+ Fix from $2,3002014-03-19 HIGH 8.8 CVE-2014-1497 The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonke… Firefox 24.4 / 28.0+ Fix from $1,9502014-03-19 HIGH 9.3 CVE-2013-0778 The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attacker… Firefox 2.16 / 17.0.3+ Fix from $1,9502013-02-19 HIGH 9.3 CVE-2013-0779EPSS 5% The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attac… Firefox 2.16 / 17.0.3+ Fix from $1,9502013-02-19 HIGH 10.0 CVE-2013-0767EPSS 6% The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird… Firefox 2.15 / 10.0.12+ Fix from $1,9502013-01-13 HIGH 9.3 CVE-2012-3995EPSS 5% The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x befo… Firefox 10.0.8 / 16.0+ Fix from $1,9502012-10-10