Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Firefox CRITICAL 9.8
CVE-2026-16407

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16387

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 1…

Fix: 140.13.0 / 153.0+
Fix from $2,300 2026-07-21
Firefox HIGH 8.8
CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox CRITICAL 10.0
CVE-2026-2768

Sandbox escape in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird …

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 10.0
CVE-2026-0881

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

Fix: 147.0+
Fix from $2,300 2026-01-13
Firefox MEDIUM 6.5
CVE-2025-11716

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 1…

Fix: 144.0+
Fix from $1,600 2025-10-14
Firefox CRITICAL 9.1
CVE-2025-1941

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE…

Fix: 136.0+
Fix from $2,300 2025-03-04
Firefox HIGH 8.1
CVE-2024-7525

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of r…

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox MEDIUM 5.3
CVE-2024-5687

If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. …

Fix: 127.0+
Fix from $1,600 2024-06-11
Firefox HIGH 8.8
CVE-2016-5283

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFR…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 8.8
CVE-2016-5273

The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote atta…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox MEDIUM 6.5
CVE-2016-2816

Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replac…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 6.8
CVE-2015-7184

The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user cre…

Fix: after 41.0.1
Fix from $1,600 2015-10-18
Firefox MEDIUM 6.8
CVE-2014-1589

Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypas…

Fix: after 33.0
Fix from $1,600 2014-12-11