Vulnerability index

Browse CVEs

99 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. Firefox 153.0 / 153.0.0+ Fix from $1,9502026-07-21 CRITICAL 9.6 CVE-2026-8959 Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, … Firefox 140.11 / 140.11.0+ Fix from $2,3002026-05-19 MEDIUM 5.3 CVE-2026-8391 Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderb… Firefox 150.0.3+ Fix from $1,6002026-05-12 MEDIUM 5.3 CVE-2026-6777 Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-6779 Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 HIGH 8.0 CVE-2026-0878 Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR … Firefox 140.7.0 / 147.0+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2025-6703 Improper Input Validation vulnerability in Mozilla neqo leads to an unexploitable crash..This issue affects neqo: from 0.4.24 through 0.13.2. Neqo after 0.13.2 Fix from $1,6002025-06-26 CRITICAL 9.8 CVE-2022-34476 ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability af… Firefox 102.0+ Fix from $2,3002022-12-22 CRITICAL 10.0 CVE-2020-12388 The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir… Firefox 68.8.0 / 76.0+ Fix from $2,3002020-05-26 CRITICAL 10.0 CVE-2020-12389 The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir… Firefox 68.8.0 / 76.0+ Fix from $2,3002020-05-26 MEDIUM 6.5 CVE-2013-1689 Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. Firefox after 19.0.2 Fix from $1,6002019-12-10 CRITICAL 10.0 CVE-2019-11708 KEVEPSS 56% Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent … Firefox 60.7.2 / 67.0.4+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11714 Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerabili… Firefox 68.0+ Fix from $2,3002019-07-23 HIGH 8.3 CVE-2019-11716 Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(… Firefox 68.0+ Fix from $1,9502019-07-23 HIGH 7.8 CVE-2019-11696 Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can… Firefox 67.0+ Fix from $1,9502019-07-23 MEDIUM 6.5 CVE-2019-11697 If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt d… Firefox 67.0+ Fix from $1,6002019-07-23 MEDIUM 5.3 CVE-2019-11698 If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the … Firefox 60.7.0 / 67.0+ Fix from $1,6002019-07-23 HIGH 7.5 CVE-2019-9799 Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the … Firefox 66.0+ Fix from $1,9502019-04-26 MEDIUM 5.3 CVE-2019-9801 Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on… Firefox 60.6 / 66.0+ Fix from $1,6002019-04-26 HIGH 7.5 CVE-2018-12401 Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lea… Firefox 63.0+ Fix from $1,9502019-02-28 MEDIUM 5.3 CVE-2018-12382 The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loade… Firefox No fix yet Fix from $1,6002018-10-18 HIGH 8.2 CVE-2018-5141 A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction.… Firefox 59.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2018-5138 A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel insid… Firefox 59.0+ Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2018-5111 When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site … Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5110 If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible wi… Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5121 Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an International… Firefox after 57.0.4 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7832 The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7833 Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some fon… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7837 SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57. Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7838 Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode disp… Firefox after 56.0.2 Fix from $1,6002018-06-11