Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Firefox Focus MEDIUM 6.5
CVE-2024-10474

Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing s…

Fix: 132.0+
Fix from $1,600 2024-10-29
Firefox MEDIUM 6.5
CVE-2022-46875

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This…

Fix: 102.6 / 108.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2019-17023

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS …

Fix: 72.0+
Fix from $1,600 2020-01-08
Firefox CRITICAL 9.8
CVE-2019-11733

When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found …

Fix: 68.0.2+
Fix from $2,300 2019-09-27
Firefox CRITICAL 10.0
CVE-2018-18505

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and…

Fix: 60.5.0 / 65.0+
Fix from $2,300 2019-02-05
Firefox MEDIUM 5.0
CVE-2013-0759

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a…

Fix: 2.15 / 10.0.12+
Fix from $1,600 2013-01-13
Bugzilla MEDIUM 6.8
CVE-2011-3667

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, …

Mitigation only
Fix from $1,600 2012-01-02
Firefox MEDIUM 6.8
CVE-2009-2065

Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows m…

Fix: after 3.0.9
Fix from $1,600 2009-06-15
Firefox MEDIUM 6.8
CVE-2009-1836

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a docume…

Fix: after 3.0.10
Fix from $1,600 2009-06-12
Firefox HIGH 7.5
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaM…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 7.5
CVE-2008-2801

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Firefox MEDIUM 5.0
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Ba…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27