Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Firefox HIGH 7.5
CVE-2025-13025

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

Fix: 145.0+
Fix from $1,950 2025-11-11
Firefox CRITICAL 9.8
CVE-2025-8031

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vuln…

Fix: 128.13.0 / 140.1.0+
Fix from $2,300 2025-07-22
Firefox HIGH 8.1
CVE-2024-7525

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of r…

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Thunderbird HIGH 7.8
CVE-2022-3155

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received fil…

Fix: 102.3+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-29909

Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing pro…

Fix: 91.9 / 100.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2020-12415

When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirector…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12424

When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2019-11765

A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However,…

Fix: 70.0+
Fix from $1,600 2020-01-08
Firefox HIGH 7.8
CVE-2017-7794

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only …

Fix: 55.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7761

The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with c…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11