Vulnerability index

Browse CVEs

99 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Bugzilla HIGH 7.5
CVE-2015-4499

Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during acco…

Patch available
Fix from $1,950 2015-09-14
Firefox MEDIUM 6.8
CVE-2015-2727

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chro…

Mitigation only
Fix from $1,600 2015-07-06
Firefox MEDIUM 6.8
CVE-2014-1594

Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1587

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 5.0
CVE-2014-1539

Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a D…

Fix: after 29.0.1
Fix from $1,600 2014-06-11
Network Security Services HIGH 7.5
CVE-2013-5605

Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly ha…

Patch available
Fix from $1,950 2013-11-18
Firefox HIGH 9.3
CVE-2013-1735

Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thund…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1731

Untrusted search path vulnerability in the GL tracing functionality in Mozilla Firefox before 24.0 on Android allows attackers to execute arbitrary c…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox HIGH 10.0
CVE-2013-1710EPSS 40%

The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17…

Fix: after 22.0
Fix from $1,950 2013-08-07
Firefox HIGH 7.5
CVE-2013-1694

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.…

Fix: after 21.0
Fix from $1,950 2013-06-26
Firefox HIGH 9.3
CVE-2013-0757EPSS 61%

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird…

Fix: 2.15 / 17.0.2+
Fix from $1,950 2013-01-13
Firefox MEDIUM 6.8
CVE-2013-0747

The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0…

Fix: 2.15 / 17.0.2+
Fix from $1,600 2013-01-13
Firefox HIGH 7.5
CVE-2012-0463

The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird …

Fix: after 10.0
Fix from $1,950 2012-03-14
Firefox HIGH 9.3
CVE-2011-3647

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the lo…

Fix: after 3.6.23
Fix from $1,950 2011-11-09
Bugzilla MEDIUM 5.0
CVE-2011-2978

Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1…

Patch available
Fix from $1,600 2011-08-09
Firefox HIGH 10.0
CVE-2011-0073EPSS 70%

Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows r…

Fix: after 2.0.13
Fix from $1,950 2011-05-07
Firefox MEDIUM 5.0
CVE-2011-0067

Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allow…

Fix: after 2.0.13
Fix from $1,600 2011-05-07
Firefox MEDIUM 6.8
CVE-2011-0051

Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, does not properly handle certain recursive eval calls, which make…

Fix: after 2.0.11
Fix from $1,600 2011-03-02
Firefox HIGH 9.3
CVE-2010-3768

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly …

Fix: after 3.5.15
Fix from $1,950 2010-12-10
Firefox HIGH 9.3
CVE-2010-1585

The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before…

Fix: after 3.1.7
Fix from $1,950 2010-04-28
Firefox HIGH 9.3
CVE-2009-4102

Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary c…

Fix: after 1.4.3
Fix from $1,950 2009-11-29
Firefox MEDIUM 5.0
CVE-2009-3078

Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and sp…

Fix: after 3.0.13
Fix from $1,600 2009-09-10
Firefox MEDIUM 5.0
CVE-2009-2470

Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a…

Fix: after 3.5.1
Fix from $1,600 2009-08-04
Firefox MEDIUM 5.8
CVE-2009-2654

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a…

Fix: after 3.5.1
Fix from $1,600 2009-08-03
Firefox MEDIUM 6.8
CVE-2009-1307

The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, w…

Fix: after 3.0.8
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.8
CVE-2009-0777

Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the loc…

Fix: after 3.0.6
Fix from $1,600 2009-03-05
Firefox MEDIUM 5.0
CVE-2008-5715EPSS 9%

Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long strin…

No fix yet
Fix from $1,600 2008-12-24
Firefox HIGH 10.0
CVE-2008-5014EPSS 6%

jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows …

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 7.5
CVE-2008-5023

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 7.5
CVE-2008-2806

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary …

Mitigation only
Fix from $1,950 2008-07-07