Vulnerability index

Browse CVEs

109 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.9 CVE-2017-5384 Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information tha… Firefox 51.0+ Fix from $1,6002018-06-11 MEDIUM 5.9 CVE-2016-9074 An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NS… Firefox 45.5.0 / 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.9 CVE-2016-5288 Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This i… Firefox 49.0.2+ Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2016-5282 Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive informa… Firefox after 48.0.2 Fix from $1,6002016-09-22 MEDIUM 6.5 CVE-2016-5260 Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which mig… Firefox after 47.0.1 Fix from $1,6002016-08-05 MEDIUM 6.5 CVE-2016-2813 Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to … Firefox after 45.0.2 Fix from $1,6002016-04-30 MEDIUM 6.5 CVE-2016-1967 Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass … Firefox after 44.0.2 Fix from $1,6002016-03-13 MEDIUM 5.3 CVE-2016-1939 Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive informati… Firefox after 43.0.4 Fix from $1,6002016-01-31 MEDIUM 5.0 CVE-2015-7214EPSS 6% Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs. Firefox after 42.0 Fix from $1,6002015-12-16 MEDIUM 5.0 CVE-2015-7208 Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by readi… Firefox after 42.0 Fix from $1,6002015-12-16 MEDIUM 5.0 CVE-2015-7207 Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass … Firefox after 42.0 Fix from $1,6002015-12-16 MEDIUM 5.0 CVE-2015-7195 The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which al… Firefox after 41.0.2 Fix from $1,6002015-11-05 MEDIUM 5.0 CVE-2015-7190 The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access thi… Firefox after 41.0.2 Fix from $1,6002015-11-05 MEDIUM 5.0 CVE-2015-4503 The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open… Firefox after 40.0.3 Fix from $1,6002015-09-24 MEDIUM 5.0 CVE-2015-0800 The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for quer… Firefox after 36.0.4 Fix from $1,6002015-04-01 MEDIUM 5.0 CVE-2014-8637 Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensi… Firefox after 34.0.5 Fix from $1,6002015-01-14 MEDIUM 5.0 CVE-2014-1580 Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from pr… Firefox after 32.0 Fix from $1,6002014-10-15 HIGH 7.5 CVE-2014-1505 The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows… Firefox 24.4 / 28.0+ Fix from $1,9502014-03-19 MEDIUM 5.0 CVE-2014-1484 Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitiv… Firefox after 26.0 Fix from $1,6002014-02-06 MEDIUM 5.0 CVE-2013-0786 The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error mess… Bugzilla after 3.6.12 Fix from $1,6002013-02-24 MEDIUM 5.0 CVE-2012-4197 Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x… Bugzilla Patch available Fix from $1,6002012-11-16 MEDIUM 5.0 CVE-2012-5884 The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches… Bugzilla Mitigation only Fix from $1,6002012-11-16 MEDIUM 5.0 CVE-2012-3972 The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, T… Firefox 10.0.7 / 15.0+ Fix from $1,6002012-08-29 MEDIUM 5.0 CVE-2012-1960 The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and S… Firefox after 2.10 Fix from $1,6002012-07-18 MEDIUM 5.0 CVE-2012-0456 The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5… Firefox after 10.0 Fix from $1,6002012-03-14 MEDIUM 5.0 CVE-2012-0447 Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon i… Firefox after 2.7 Fix from $1,6002012-02-01 MEDIUM 5.0 CVE-2011-3670 Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce th… Firefox after 3.6.25 Fix from $1,6002012-02-01 MEDIUM 5.0 CVE-2011-3653 Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel… Firefox after 7.0.1 Fix from $1,6002011-11-09 MEDIUM 5.0 CVE-2011-2986 Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used o… Firefox after 5.0 Fix from $1,6002011-08-18 MEDIUM 5.0 CVE-2011-2380 Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.… Bugzilla Patch available Fix from $1,6002011-08-09