Vulnerability index

Browse CVEs

109 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Firefox MEDIUM 5.9
CVE-2017-5384

Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information tha…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-9074

An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NS…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-5288

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This i…

Fix: 49.0.2+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5282

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive informa…

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Firefox MEDIUM 6.5
CVE-2016-5260

Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which mig…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox MEDIUM 6.5
CVE-2016-2813

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to …

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 6.5
CVE-2016-1967

Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass …

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Firefox MEDIUM 5.3
CVE-2016-1939

Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive informati…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 5.0
CVE-2015-7214EPSS 6%

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7208

Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by readi…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7207

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass …

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7195

The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which al…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox MEDIUM 5.0
CVE-2015-7190

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access thi…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox MEDIUM 5.0
CVE-2015-4503

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 5.0
CVE-2015-0800

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for quer…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox MEDIUM 5.0
CVE-2014-8637

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensi…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Firefox MEDIUM 5.0
CVE-2014-1580

Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from pr…

Fix: after 32.0
Fix from $1,600 2014-10-15
Firefox HIGH 7.5
CVE-2014-1505

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox MEDIUM 5.0
CVE-2014-1484

Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitiv…

Fix: after 26.0
Fix from $1,600 2014-02-06
Bugzilla MEDIUM 5.0
CVE-2013-0786

The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error mess…

Fix: after 3.6.12
Fix from $1,600 2013-02-24
Bugzilla MEDIUM 5.0
CVE-2012-4197

Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x…

Patch available
Fix from $1,600 2012-11-16
Bugzilla MEDIUM 5.0
CVE-2012-5884

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches…

Mitigation only
Fix from $1,600 2012-11-16
Firefox MEDIUM 5.0
CVE-2012-3972

The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, T…

Fix: 10.0.7 / 15.0+
Fix from $1,600 2012-08-29
Firefox MEDIUM 5.0
CVE-2012-1960

The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and S…

Fix: after 2.10
Fix from $1,600 2012-07-18
Firefox MEDIUM 5.0
CVE-2012-0456

The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5…

Fix: after 10.0
Fix from $1,600 2012-03-14
Firefox MEDIUM 5.0
CVE-2012-0447

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon i…

Fix: after 2.7
Fix from $1,600 2012-02-01
Firefox MEDIUM 5.0
CVE-2011-3670

Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce th…

Fix: after 3.6.25
Fix from $1,600 2012-02-01
Firefox MEDIUM 5.0
CVE-2011-3653

Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel…

Fix: after 7.0.1
Fix from $1,600 2011-11-09
Firefox MEDIUM 5.0
CVE-2011-2986

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used o…

Fix: after 5.0
Fix from $1,600 2011-08-18
Bugzilla MEDIUM 5.0
CVE-2011-2380

Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.…

Patch available
Fix from $1,600 2011-08-09