Vulnerability index

Browse CVEs

99 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Firefox HIGH 7.5
CVE-2026-16378

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox CRITICAL 9.6
CVE-2026-8959

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, …

Fix: 140.11 / 140.11.0+
Fix from $2,300 2026-05-19
Firefox MEDIUM 5.3
CVE-2026-8391

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb…

Fix: 150.0.3+
Fix from $1,600 2026-05-12
Firefox MEDIUM 5.3
CVE-2026-6777

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox MEDIUM 5.3
CVE-2026-6779

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox HIGH 8.0
CVE-2026-0878

Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR …

Fix: 140.7.0 / 147.0+
Fix from $1,950 2026-01-13
Neqo MEDIUM 6.5
CVE-2025-6703

Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2.

Fix: after 0.13.2
Fix from $1,600 2025-06-26
Firefox CRITICAL 9.8
CVE-2022-34476

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability af…

Fix: 102.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 10.0
CVE-2020-12388

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 10.0
CVE-2020-12389

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox MEDIUM 6.5
CVE-2013-1689

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

Fix: after 19.0.2
Fix from $1,600 2019-12-10
Firefox CRITICAL 10.0
CVE-2019-11708 KEVEPSS 56%

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent …

Fix: 60.7.2 / 67.0.4+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11714

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerabili…

Fix: 68.0+
Fix from $2,300 2019-07-23
Firefox HIGH 8.3
CVE-2019-11716

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(…

Fix: 68.0+
Fix from $1,950 2019-07-23
Firefox HIGH 7.8
CVE-2019-11696

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can…

Fix: 67.0+
Fix from $1,950 2019-07-23
Firefox MEDIUM 6.5
CVE-2019-11697

If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt d…

Fix: 67.0+
Fix from $1,600 2019-07-23
Firefox MEDIUM 5.3
CVE-2019-11698

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the …

Fix: 60.7.0 / 67.0+
Fix from $1,600 2019-07-23
Firefox HIGH 7.5
CVE-2019-9799

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the …

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox MEDIUM 5.3
CVE-2019-9801

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on…

Fix: 60.6 / 66.0+
Fix from $1,600 2019-04-26
Firefox HIGH 7.5
CVE-2018-12401

Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lea…

Fix: 63.0+
Fix from $1,950 2019-02-28
Firefox MEDIUM 5.3
CVE-2018-12382

The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loade…

No fix yet
Fix from $1,600 2018-10-18
Firefox HIGH 8.2
CVE-2018-5141

A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction.…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5138

A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel insid…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5111

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site …

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5110

If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible wi…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5121

Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an International…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7832

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7833

Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some fon…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7837

SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57.

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7838

Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode disp…

Fix: after 56.0.2
Fix from $1,600 2018-06-11