Vulnerability index

Browse CVEs

103 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Firefox MEDIUM 5.4
CVE-2013-1717

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20…

Fix: after 22.0
Fix from $1,600 2013-08-07
Firefox HIGH 9.3
CVE-2013-1687

The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunder…

Fix: after 21.0
Fix from $1,950 2013-06-26
Firefox HIGH 9.3
CVE-2013-1697

The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x be…

Fix: after 21.0
Fix from $1,950 2013-06-26
Firefox HIGH 7.2
CVE-2013-1700

The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable…

Fix: after 21.0
Fix from $1,950 2013-06-26
Firefox MEDIUM 5.0
CVE-2013-1695

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which a…

Fix: after 21.0
Fix from $1,600 2013-06-26
Firefox MEDIUM 6.9
CVE-2013-1672

The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x b…

Fix: after 20.0.1
Fix from $1,600 2013-05-16
Firefox MEDIUM 6.9
CVE-2013-1673

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situ…

Fix: after 20.0.1
Fix from $1,600 2013-05-16
Firefox HIGH 10.0
CVE-2013-0795

The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird E…

Fix: after 19.0.2
Fix from $1,950 2013-04-03
Firefox MEDIUM 5.8
CVE-2013-0751

Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attack…

Fix: after 17.0.1
Fix from $1,600 2013-01-13
Firefox HIGH 9.3
CVE-2012-4210

The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Casc…

Fix: after 16.0.2
Fix from $1,950 2012-11-21
Firefox MEDIUM 6.8
CVE-2012-4203

The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assiste…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Firefox HIGH 9.3
CVE-2012-3991

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 d…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Bugzilla MEDIUM 5.0
CVE-2012-4747

Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive …

Patch available
Fix from $1,600 2012-09-04
Firefox HIGH 7.6
CVE-2012-3973

The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to…

Fix: after 14.0
Fix from $1,950 2012-08-29
Firefox MEDIUM 6.8
CVE-2012-3978

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x befor…

Fix: after 14.0
Fix from $1,600 2012-08-29
Firefox HIGH 9.3
CVE-2012-3965

Mozilla Firefox before 15.0 does not properly restrict navigation to the about:newtab page, which allows remote attackers to execute arbitrary JavaSc…

Fix: after 14.0
Fix from $1,950 2012-08-29
Firefox MEDIUM 5.0
CVE-2012-1959

Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey bef…

Fix: after 2.10
Fix from $1,600 2012-07-18
Firefox HIGH 7.2
CVE-2012-1942

The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain pri…

Mitigation only
Fix from $1,950 2012-06-05
Firefox HIGH 9.3
CVE-2012-0478

The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.…

Fix: after 2.9
Fix from $1,950 2012-04-25
Firefox HIGH 7.5
CVE-2012-0459

The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Th…

Fix: after 2.7
Fix from $1,950 2012-03-14
Firefox MEDIUM 6.8
CVE-2012-0458

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 1…

Fix: after 10.0
Fix from $1,600 2012-03-14
Firefox MEDIUM 6.4
CVE-2012-0460

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey bef…

Fix: after 2.7
Fix from $1,600 2012-03-14
Firefox MEDIUM 5.0
CVE-2012-0445

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation po…

Fix: after 2.7
Fix from $1,600 2012-02-01
Firefox MEDIUM 6.8
CVE-2011-3666

Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted…

Fix: after 3.6.24
Fix from $1,600 2011-12-21
Firefox MEDIUM 5.0
CVE-2011-4688

Mozilla Firefox 8.0.1 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, w…

Fix: after 8.0.1
Fix from $1,600 2011-12-07
Firefox MEDIUM 5.0
CVE-2002-2437

The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of v…

Fix: after 3.6.24
Fix from $1,600 2011-12-07
Firefox HIGH 9.3
CVE-2011-2993

The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does n…

Mitigation only
Fix from $1,950 2011-08-18
Firefox MEDIUM 5.8
CVE-2008-7293

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to…

Fix: after 4.0
Fix from $1,600 2011-08-09
Firefox HIGH 10.0
CVE-2011-2368

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2011-06-30
Firefox MEDIUM 6.4
CVE-2011-2367

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sen…

Mitigation only
Fix from $1,600 2011-06-30