Vulnerability index

Browse CVEs

99 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Firefox MEDIUM 5.3
CVE-2017-7815

On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as th…

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7816

WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavi…

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7817

A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. Th…

Fix: after 55.0.3
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-7783EPSS 14%

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal p…

Fix: 55.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-7804

The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write a…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-7765

The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the W…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.9
CVE-2017-7770

A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This w…

Fix: 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7763

Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name s…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7764

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rend…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5463

Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of …

Fix: 53.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5450

A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, mak…

Fix: 53.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5421

A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is curre…

Fix: 52.0.+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5422

If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the h…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2017-5420

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker t…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5417

When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displa…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5415EPSS 13%

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furth…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2016-9065

The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location …

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-9076

An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e1…

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5292

During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5298

A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when the new pa…

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5291

A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firef…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5293

When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local …

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5294

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerabilit…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Bleach CRITICAL 9.8
CVE-2018-7753

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character en…

Patch available
Fix from $2,300 2018-03-07
Firefox HIGH 7.4
CVE-2016-5284

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinnin…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 8.8
CVE-2016-5272

The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast …

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox MEDIUM 5.3
CVE-2016-5267

Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-l…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox MEDIUM 6.5
CVE-2016-2839

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with …

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 7.4
CVE-2016-1942

Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a …

Fix: after 43.0.4
Fix from $1,950 2016-01-31
Firefox MEDIUM 5.0
CVE-2015-7211

Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified…

Fix: after 42.0
Fix from $1,600 2015-12-16