Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Firefox MEDIUM 5.3
CVE-2026-6777

Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox MEDIUM 6.5
CVE-2026-6755

Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox MEDIUM 6.5
CVE-2025-4088

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site tha…

Fix: 138.0+
Fix from $1,600 2025-04-29
Firefox HIGH 8.8
CVE-2023-4047

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerabil…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Geckodriver HIGH 8.8
CVE-2020-15660

Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically p…

Fix: 0.27.0+
Fix from $1,950 2021-07-20
Persona HIGH 8.8
CVE-2013-4227

Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x…

Fix: 7.x-1.11+
Fix from $1,950 2020-02-18
Firefox HIGH 8.8
CVE-2019-11712

POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attac…

Fix: 60.8.0 / 68.0+
Fix from $1,950 2019-07-23
Bugzilla HIGH 8.8
CVE-2018-5123

A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al…

Fix: 4.4+
Fix from $1,950 2019-04-29
Firefox HIGH 8.8
CVE-2017-5394

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript even…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.8
CVE-2015-0807

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x …

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox MEDIUM 6.8
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Firefox MEDIUM 6.8
CVE-2013-6167

Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows re…

Fix: after 27.0
Fix from $1,600 2014-02-15
Bugzilla MEDIUM 6.8
CVE-2013-1734

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.…

Patch available
Fix from $1,600 2013-10-24
Bugzilla MEDIUM 6.8
CVE-2013-1733

Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authenticatio…

Patch available
Fix from $1,600 2013-10-24
Firefox MEDIUM 6.8
CVE-2012-4205

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XM…

Fix: 2.14 / 17.0+
Fix from $1,600 2012-11-21
Bugzilla MEDIUM 5.1
CVE-2012-0453

Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows…

Patch available
Fix from $1,600 2012-02-25
Bugzilla MEDIUM 5.1
CVE-2012-0440

Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and …

Patch available
Fix from $1,600 2012-02-02
Bugzilla MEDIUM 6.8
CVE-2011-3668

Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the aut…

No fix yet
Fix from $1,600 2012-01-02
Bugzilla MEDIUM 6.8
CVE-2011-3669

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the a…

No fix yet
Fix from $1,600 2012-01-02
Firefox MEDIUM 6.8
CVE-2011-0059

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote …

Fix: after 2.0.11
Fix from $1,600 2011-03-02
Bugzilla MEDIUM 6.8
CVE-2011-0046

Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc…

Fix: after 3.2.9
Fix from $1,600 2011-01-28
Bugzilla MEDIUM 6.8
CVE-2009-1213

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote …

Patch available
Fix from $1,600 2009-04-01
Bugzilla HIGH 7.5
CVE-2009-0486

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the sam…

Mitigation only
Fix from $1,950 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0482

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0483

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remot…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0484

Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delet…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0485

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09