Vulnerability index

Browse CVEs

103 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Firefox CRITICAL 9.8
CVE-2016-9075

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This…

Fix: 50.0+
Fix from $2,300 2018-06-11
Firefox HIGH 8.0
CVE-2016-9070

A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operati…

Fix: 50+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9073

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox …

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.8
CVE-2016-5295

This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozil…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 8.1
CVE-2016-5266

Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote att…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 7.8
CVE-2016-2826

The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification d…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox MEDIUM 5.4
CVE-2016-2817

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inh…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 5.0
CVE-2016-2810

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that le…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 5.5
CVE-2016-2809

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by …

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox HIGH 7.4
CVE-2016-1963

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changin…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1954

The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prev…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1949

Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass…

Fix: after 44.0.1
Fix from $1,950 2016-02-13
Firefox MEDIUM 5.0
CVE-2015-7197

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allow…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox MEDIUM 6.6
CVE-2015-4505

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 5.0
CVE-2015-0798

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which…

Fix: after 37.0
Fix from $1,600 2015-04-08
Firefox MEDIUM 5.0
CVE-2015-0816EPSS 67%

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox HIGH 7.5
CVE-2015-0804

The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Firefox HIGH 7.5
CVE-2015-0801

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and ex…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Firefox HIGH 7.5
CVE-2015-0818

Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy an…

Fix: after 36.0.3
Fix from $1,950 2015-03-24
Firefox MEDIUM 6.8
CVE-2015-0821

Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Firefox HIGH 7.1
CVE-2014-8643

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging acce…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Firefox HIGH 7.5
CVE-2014-1575EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0 allow remote attackers to cause a denial of service (memory…

Fix: after 32.0
Fix from $1,950 2014-10-15
Firefox MEDIUM 5.8
CVE-2014-1552

Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote at…

Fix: after 30.0
Fix from $1,600 2014-07-23
Firefox MEDIUM 5.8
CVE-2014-1561

Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to al…

Fix: after 30.0
Fix from $1,600 2014-07-23
Firefox MEDIUM 5.0
CVE-2014-1516

The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to s…

Fix: after 28.0.1
Fix from $1,600 2014-03-29
Firefox MEDIUM 5.8
CVE-2014-1501

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving…

Fix: after 27.0.1
Fix from $1,600 2014-03-19
Network Security Services MEDIUM 5.8
CVE-2013-5606

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return va…

Mitigation only
Fix from $1,600 2013-11-18
Firefox HIGH 8.3
CVE-2013-5598

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remo…

Fix: after 24.0
Fix from $1,950 2013-10-30
Firefox MEDIUM 6.2
CVE-2013-1726

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaM…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 5.0
CVE-2013-1737

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…

Fix: after 23.0.1
Fix from $1,600 2013-09-18