Vulnerability index

Browse CVEs

103 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
CRITICAL 9.8 CVE-2016-9075 An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This… Firefox 50.0+ Fix from $2,3002018-06-11 HIGH 8.0 CVE-2016-9070 A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operati… Firefox 50+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9073 WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox … Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 7.8 CVE-2016-5295 This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozil… Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 8.1 CVE-2016-5266 Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote att… Firefox after 47.0.1 Fix from $1,9502016-08-05 HIGH 7.8 CVE-2016-2826 The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification d… Firefox after 46.0.1 Fix from $1,9502016-06-13 MEDIUM 5.4 CVE-2016-2817 The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inh… Firefox after 45.0.2 Fix from $1,6002016-04-30 MEDIUM 5.0 CVE-2016-2810 Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that le… Firefox after 45.0.2 Fix from $1,6002016-04-30 MEDIUM 5.5 CVE-2016-2809 The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by … Firefox after 45.0.2 Fix from $1,6002016-04-30 HIGH 7.4 CVE-2016-1963 The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changin… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1954 The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prev… Firefox after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1949 Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass… Firefox after 44.0.1 Fix from $1,9502016-02-13 MEDIUM 5.0 CVE-2015-7197 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allow… Firefox after 41.0.2 Fix from $1,6002015-11-05 MEDIUM 6.6 CVE-2015-4505 updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a… Firefox after 40.0.3 Fix from $1,6002015-09-24 MEDIUM 5.0 CVE-2015-0798 The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which… Firefox after 37.0 Fix from $1,6002015-04-08 MEDIUM 5.0 CVE-2015-0816EPSS 67% Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier… Firefox after 36.0.4 Fix from $1,6002015-04-01 HIGH 7.5 CVE-2015-0804 The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation… Firefox after 36.0.4 Fix from $1,9502015-04-01 HIGH 7.5 CVE-2015-0801 Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and ex… Firefox after 36.0.4 Fix from $1,9502015-04-01 HIGH 7.5 CVE-2015-0818 Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy an… Firefox after 36.0.3 Fix from $1,9502015-03-24 MEDIUM 6.8 CVE-2015-0821 Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges… Firefox after 35.0.1 Fix from $1,6002015-02-25 HIGH 7.1 CVE-2014-8643 Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging acce… Firefox after 34.0.5 Fix from $1,9502015-01-14 HIGH 7.5 CVE-2014-1575EPSS 5% Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0 allow remote attackers to cause a denial of service (memory… Firefox after 32.0 Fix from $1,9502014-10-15 MEDIUM 5.8 CVE-2014-1552 Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote at… Firefox after 30.0 Fix from $1,6002014-07-23 MEDIUM 5.8 CVE-2014-1561 Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to al… Firefox after 30.0 Fix from $1,6002014-07-23 MEDIUM 5.0 CVE-2014-1516 The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to s… Firefox after 28.0.1 Fix from $1,6002014-03-29 MEDIUM 5.8 CVE-2014-1501 Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving… Firefox after 27.0.1 Fix from $1,6002014-03-19 MEDIUM 5.8 CVE-2013-5606 The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return va… Network Security Services Mitigation only Fix from $1,6002013-11-18 HIGH 8.3 CVE-2013-5598 PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remo… Firefox after 24.0 Fix from $1,9502013-10-30 MEDIUM 6.2 CVE-2013-1726 Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaM… Firefox after 23.0.1 Fix from $1,6002013-09-18 MEDIUM 5.0 CVE-2013-1737 Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d… Firefox after 23.0.1 Fix from $1,6002013-09-18