Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.3 CVE-2026-6777 Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-6755 Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2025-4088 A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site tha… Firefox 138.0+ Fix from $1,6002025-04-29 HIGH 8.8 CVE-2023-4047 A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerabil… Firefox 102.14 / 115.1+ Fix from $1,9502023-08-01 HIGH 8.8 CVE-2020-15660 Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically p… Geckodriver 0.27.0+ Fix from $1,9502021-07-20 HIGH 8.8 CVE-2013-4227 Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x… Persona 7.x-1.11+ Fix from $1,9502020-02-18 HIGH 8.8 CVE-2019-11712 POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attac… Firefox 60.8.0 / 68.0+ Fix from $1,9502019-07-23 HIGH 8.8 CVE-2018-5123 A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al… Bugzilla 4.4+ Fix from $1,9502019-04-29 HIGH 8.8 CVE-2017-5394 A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript even… Firefox 51.0+ Fix from $1,9502018-06-11 MEDIUM 6.8 CVE-2015-0807 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x … Firefox after 36.0.4 Fix from $1,6002015-04-01 MEDIUM 6.8 CVE-2014-8638 The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2… Firefox after 34.0.5 Fix from $1,6002015-01-14 MEDIUM 6.8 CVE-2013-6167 Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows re… Firefox after 27.0 Fix from $1,6002014-02-15 MEDIUM 6.8 CVE-2013-1734 Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.… Bugzilla Patch available Fix from $1,6002013-10-24 MEDIUM 6.8 CVE-2013-1733 Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authenticatio… Bugzilla Patch available Fix from $1,6002013-10-24 MEDIUM 6.8 CVE-2012-4205 Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XM… Firefox 2.14 / 17.0+ Fix from $1,6002012-11-21 MEDIUM 5.1 CVE-2012-0453 Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows… Bugzilla Patch available Fix from $1,6002012-02-25 MEDIUM 5.1 CVE-2012-0440 Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and … Bugzilla Patch available Fix from $1,6002012-02-02 MEDIUM 6.8 CVE-2011-3668 Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the aut… Bugzilla No fix yet Fix from $1,6002012-01-02 MEDIUM 6.8 CVE-2011-3669 Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the a… Bugzilla No fix yet Fix from $1,6002012-01-02 MEDIUM 6.8 CVE-2011-0059 Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote … Firefox after 2.0.11 Fix from $1,6002011-03-02 MEDIUM 6.8 CVE-2011-0046 Multiple cross-site request forgery (CSRF) vulnerabilities in Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc… Bugzilla after 3.2.9 Fix from $1,6002011-01-28 MEDIUM 6.8 CVE-2009-1213 Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote … Bugzilla Patch available Fix from $1,6002009-04-01 HIGH 7.5 CVE-2009-0486 Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the sam… Bugzilla Mitigation only Fix from $1,9502009-02-09 MEDIUM 5.8 CVE-2009-0482 Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote at… Bugzilla Mitigation only Fix from $1,6002009-02-09 MEDIUM 5.8 CVE-2009-0483 Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remot… Bugzilla Mitigation only Fix from $1,6002009-02-09 MEDIUM 5.8 CVE-2009-0484 Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delet… Bugzilla Mitigation only Fix from $1,6002009-02-09 MEDIUM 5.8 CVE-2009-0485 Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote at… Bugzilla Mitigation only Fix from $1,6002009-02-09