Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Firefox HIGH 8.8
CVE-2016-1968

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox CRITICAL 9.8
CVE-2016-1946EPSS 6%

The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operatio…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox MEDIUM 6.5
CVE-2016-1933

Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 6.8
CVE-2015-7222

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7219

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, …

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox HIGH 7.5
CVE-2015-7183EPSS 7%

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 9.3
CVE-2015-4496

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metad…

Fix: after 37.0.2
Fix from $1,950 2015-08-16
Firefox HIGH 10.0
CVE-2015-4479EPSS 9%

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitr…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox Os MEDIUM 5.0
CVE-2015-5962

Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics…

Fix: after 2.1.0
Fix from $1,600 2015-08-08
Firefox MEDIUM 6.8
CVE-2015-2717

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (hea…

Fix: after 37.0.2
Fix from $1,600 2015-05-14
Firefox HIGH 7.5
CVE-2013-5607

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefo…

Fix: after 4.10.1
Fix from $1,950 2013-11-20
Network Security Services HIGH 7.5
CVE-2013-1741

Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have …

Mitigation only
Fix from $1,950 2013-11-18
Firefox HIGH 9.3
CVE-2012-3969

Integer overflow in the nsSVGFEMorphologyElement::Filter function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before …

Fix: after 14.0
Fix from $1,950 2012-08-29
Firefox MEDIUM 5.0
CVE-2012-0473

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thu…

Fix: after 2.9
Fix from $1,600 2012-04-25
Firefox HIGH 10.0
CVE-2011-2998EPSS 5%

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute…

Mitigation only
Fix from $1,950 2011-09-30
Firefox HIGH 10.0
CVE-2011-2371EPSS 76%

Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey thr…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-1300

The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engi…

Fix: 10.0.648.205+
Fix from $1,950 2011-04-15
Firefox HIGH 9.3
CVE-2010-3767

Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote atta…

Fix: after 3.5.15
Fix from $1,950 2010-12-10
Firefox HIGH 9.3
CVE-2010-3772

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child conten…

Fix: after 3.5.15
Fix from $1,950 2010-12-10
Firefox HIGH 9.3
CVE-2010-2765EPSS 6%

Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x b…

Fix: after 3.5.11
Fix from $1,950 2010-09-09
Firefox HIGH 9.3
CVE-2010-2752EPSS 10%

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-1214EPSS 8%

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitr…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-1196

Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird bef…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1199EPSS 11%

Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1028EPSS 9%

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.…

Mitigation only
Fix from $1,950 2010-03-19
Firefox HIGH 9.3
CVE-2009-3389

Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote at…

Fix: after 2.0
Fix from $1,950 2009-12-17
Firefox HIGH 10.0
CVE-2009-2463EPSS 6%

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.…

Patch available
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2468EPSS 6%

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox MEDIUM 5.0
CVE-2009-2535EPSS 9%

Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumpt…

Fix: after 2.0.0.18
Fix from $1,600 2009-07-20
Firefox MEDIUM 5.0
CVE-2009-2478EPSS 8%

Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, re…

No fix yet
Fix from $1,600 2009-07-16