Vulnerability index

Browse CVEs

46 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Firefox HIGH 8.3
CVE-2019-9818

A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in t…

Fix: 60.7 / 67.0+
Fix from $1,950 2019-07-23
Firefox HIGH 8.1
CVE-2019-9821

A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable…

Fix: 67.0+
Fix from $1,950 2019-07-23
Firefox MEDIUM 5.5
CVE-2017-5427

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local …

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.0
CVE-2016-9077

Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-2812

Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remo…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox MEDIUM 6.3
CVE-2016-1975

Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might al…

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Firefox Os MEDIUM 6.4
CVE-2015-8511

Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requir…

Fix: after 2.2
Fix from $1,600 2016-01-09
Firefox MEDIUM 6.8
CVE-2015-7189

Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitra…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox MEDIUM 6.8
CVE-2015-4510

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or caus…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 6.8
CVE-2015-2715

Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary cod…

Fix: after 37.0.2
Fix from $1,600 2015-05-14
Firefox MEDIUM 6.8
CVE-2015-2706

Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary…

Fix: after 37.0.1
Fix from $1,600 2015-04-27
Firefox MEDIUM 5.0
CVE-2014-8640

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey b…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Firefox HIGH 9.3
CVE-2014-1490

Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24…

Fix: 2.24 / 3.15.4+
Fix from $1,950 2014-02-06
Firefox MEDIUM 5.8
CVE-2009-4129

Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in…

Mitigation only
Fix from $1,600 2009-12-14
Firefox HIGH 7.5
CVE-2009-1837

Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 mig…

Fix: 3.0.11+
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remo…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13