Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2024-10474 Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing s… Firefox Focus 132.0+ Fix from $1,6002024-10-29 MEDIUM 6.5 CVE-2022-46875 The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This… Firefox 102.6 / 108.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2019-17023 After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS … Firefox 72.0+ Fix from $1,6002020-01-08 CRITICAL 9.8 CVE-2019-11733 When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found … Firefox 68.0.2+ Fix from $2,3002019-09-27 CRITICAL 10.0 CVE-2018-18505 An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and… Firefox 60.5.0 / 65.0+ Fix from $2,3002019-02-05 MEDIUM 5.0 CVE-2013-0759 Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a… Firefox 2.15 / 10.0.12+ Fix from $1,6002013-01-13 MEDIUM 6.8 CVE-2011-3667 The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, … Bugzilla Mitigation only Fix from $1,6002012-01-02 MEDIUM 6.8 CVE-2009-2065 Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows m… Firefox after 3.0.9 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-1836 Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a docume… Firefox after 3.0.10 Fix from $1,6002009-06-12 HIGH 7.5 CVE-2008-5022 The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaM… Firefox 1.1.13 / 2.0.0.18+ Fix from $1,9502008-11-13 HIGH 7.5 CVE-2008-2801 Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary… Firefox after 2.0.0.14 Fix from $1,9502008-07-07 MEDIUM 5.0 CVE-2008-1238 Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Ba… Firefox after 2.0.0.12 Fix from $1,6002008-03-27