Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Firefox CRITICAL 9.8
CVE-2025-6433

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the …

Fix: 140.0+
Fix from $2,300 2025-06-24
Firefox HIGH 8.8
CVE-2025-1014

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fi…

Fix: 128.7.0 / 135.0+
Fix from $1,950 2025-02-04
Thunderbird MEDIUM 6.5
CVE-2023-0430

Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as hav…

Fix: 102.7.1+
Fix from $1,600 2023-06-02
Thunderbird MEDIUM 6.5
CVE-2023-0547

OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thu…

Fix: 102.10+
Fix from $1,600 2023-06-02
Firefox MEDIUM 6.5
CVE-2022-45419

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and…

Fix: 107.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.1
CVE-2022-34469

When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. …

Fix: 102.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22747

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is …

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Thunderbird MEDIUM 6.5
CVE-2022-1834

When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would hav…

Fix: 91.10+
Fix from $1,600 2022-12-22
Thunderbird MEDIUM 5.4
CVE-2022-1197

When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was…

Fix: 91.8+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2007-5967

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

Mitigation only
Fix from $1,600 2021-05-17
Network Security Services HIGH 7.5
CVE-2019-17007

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

Fix: 2.14.0 / 3.44+
Fix from $1,950 2020-10-22
Firefox MEDIUM 6.5
CVE-2020-12421

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an admini…

Fix: 68.10.0 / 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2011-2669

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

Fix: 3.6+
Fix from $1,600 2020-01-21
Firefox MEDIUM 5.3
CVE-2019-11727

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those ar…

Fix: 68.0+
Fix from $1,600 2019-07-23
Firefox MEDIUM 5.9
CVE-2016-9064

Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perfor…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Zamboni HIGH 7.4
CVE-2012-5822

The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,950 2012-11-04
Firefox MEDIUM 5.9
CVE-2009-2408EPSS 6%

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properl…

Fix: 1.1.18 / 2.0.0.23+
Fix from $1,600 2009-07-30