Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Firefox MEDIUM 5.3
CVE-2016-1948

Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attack…

Mitigation only
Fix from $1,600 2016-01-31
Firefox MEDIUM 6.5
CVE-2016-1938

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, imprope…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Network Security Services MEDIUM 5.8
CVE-2013-1740

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is…

Fix: after 3.15.3
Fix from $1,600 2014-01-18
Firefox MEDIUM 5.0
CVE-2013-1699

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level…

Fix: after 21.0
Fix from $1,600 2013-06-26
Firefox HIGH 7.5
CVE-2010-3173

The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey befor…

Fix: after 3.5.13
Fix from $1,950 2010-10-21
Firefox MEDIUM 5.8
CVE-2010-3171

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random …

No fix yet
Fix from $1,600 2010-09-15
Firefox MEDIUM 5.8
CVE-2010-3399

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a conte…

No fix yet
Fix from $1,600 2010-09-15
Firefox MEDIUM 5.8
CVE-2010-3400

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5…

Fix: after 2.0.4
Fix from $1,600 2010-09-15
Bugzilla MEDIUM 6.5
CVE-2010-2757

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonat…

Mitigation only
Fix from $1,600 2010-08-16
Firefox HIGH 9.3
CVE-2009-2061

Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to ex…

Fix: after 3.0.9
Fix from $1,950 2009-06-15