Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
CRITICAL 9.8 CVE-2025-6433 If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the … Firefox 140.0+ Fix from $2,3002025-06-24 HIGH 8.8 CVE-2025-1014 Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fi… Firefox 128.7.0 / 135.0+ Fix from $1,9502025-02-04 MEDIUM 6.5 CVE-2023-0430 Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as hav… Thunderbird 102.7.1+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-0547 OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thu… Thunderbird 102.10+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2022-45419 If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and… Firefox 107.0+ Fix from $1,6002022-12-22 HIGH 8.1 CVE-2022-34469 When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. … Firefox 102.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-22747 After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is … Firefox 91.5 / 96.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-1834 When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would hav… Thunderbird 91.10+ Fix from $1,6002022-12-22 MEDIUM 5.4 CVE-2022-1197 When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was… Thunderbird 91.8+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2007-5967 A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval. Firefox Mitigation only Fix from $1,6002021-05-17 HIGH 7.5 CVE-2019-17007 In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. Network Security Services 2.14.0 / 3.44+ Fix from $1,9502020-10-22 MEDIUM 6.5 CVE-2020-12421 When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an admini… Firefox 68.10.0 / 78.0+ Fix from $1,6002020-07-09 MEDIUM 6.5 CVE-2011-2669 Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates. Firefox 3.6+ Fix from $1,6002020-01-21 MEDIUM 5.3 CVE-2019-11727 A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those ar… Firefox 68.0+ Fix from $1,6002019-07-23 MEDIUM 5.9 CVE-2016-9064 Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perfor… Firefox 45.5.0 / 50.0+ Fix from $1,6002018-06-11 HIGH 7.4 CVE-2012-5822 The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam… Zamboni No fix yet Fix from $1,9502012-11-04 MEDIUM 5.9 CVE-2009-2408EPSS 6% Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properl… Firefox 1.1.18 / 2.0.0.23+ Fix from $1,6002009-07-30