Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Firefox HIGH 8.8
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking be…

Fix: 115.23.0 / 128.10.0+
Fix from $1,950 2025-04-29
Thunderbird MEDIUM 6.3
CVE-2025-2830

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /…

Fix: 128.9.2 / 137.0.2+
Fix from $1,600 2025-04-15
Firefox MEDIUM 6.5
CVE-2023-6209

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specifi…

Fix: 115.5 / 115.5.0+
Fix from $1,600 2023-11-21
Firefox MEDIUM 6.5
CVE-2023-28163

When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resol…

Fix: 102.9 / 111.0+
Fix from $1,600 2023-06-02
Firefox MEDIUM 5.5
CVE-2020-12392

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. …

Fix: 68.8.0 / 76.0+
Fix from $1,600 2020-05-26
Firefox Esr HIGH 7.5
CVE-2020-6828

A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrit…

Fix: 68.7.0+
Fix from $1,950 2020-04-24
Firefox HIGH 7.5
CVE-2017-5381

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allow…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefoxos HIGH 9.3
CVE-2014-1507

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection …

Fix: after 1.2
Fix from $1,950 2014-03-19
Firefox MEDIUM 6.4
CVE-2014-1506

Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of…

Fix: after 27.0.1
Fix from $1,600 2014-03-19
Firefox MEDIUM 5.0
CVE-2011-0071

Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on…

Fix: after 3.1.9
Fix from $1,600 2011-05-07
Bugzilla HIGH 7.1
CVE-2008-4437EPSS 6%

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attac…

Patch available
Fix from $1,950 2008-10-03
Firefox HIGH 7.8
CVE-2008-4068

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 a…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 7.1
CVE-2007-3072

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot enc…

No fix yet
Fix from $1,950 2007-06-06