Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Firefox CRITICAL 9.8
CVE-2020-15684

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 82.0+
Fix from $2,300 2020-10-22
Firefox Esr HIGH 8.8
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-fr…

Fix: 68.12+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15670

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we pres…

Fix: 78.2 / 80.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15673

Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption an…

Fix: 78.3 / 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15675

When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnera…

Fix: 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15678

When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs be…

Fix: 78.3 / 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-12416

A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption…

Fix: 78.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12419

When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free conditi…

Fix: 68.10 / 68.10.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12420

When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potenti…

Fix: 68.10.0 / 78.0+
Fix from $1,950 2020-07-09
Firefox MEDIUM 5.3
CVE-2020-12405

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerabili…

Fix: 68.9.0 / 77.0+
Fix from $1,600 2020-07-09
Firefox HIGH 8.1
CVE-2020-12387

A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. T…

Fix: 68.8.0 / 76.0+
Fix from $1,950 2020-05-26
Firefox HIGH 8.1
CVE-2020-6819 KEV

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Firefox HIGH 8.8
CVE-2020-6805

When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially explo…

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Firefox HIGH 8.8
CVE-2020-6807

When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was d…

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Firefox HIGH 8.8
CVE-2019-17013

Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 71.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-17008

When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerabili…

Fix: 68.3 / 71.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-11756

Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability…

Fix: 71.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-11757

When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulte…

Fix: 68.2 / 70.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-11752

It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentia…

Fix: 60.9.0 / 68.1.0+
Fix from $1,950 2019-09-27
Firefox HIGH 8.8
CVE-2019-11746

A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exp…

Fix: 60.9.0 / 68.1.0+
Fix from $1,950 2019-09-27
Firefox CRITICAL 9.8
CVE-2019-9820

A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable c…

Fix: 60.7 / 60.7.0+
Fix from $2,300 2019-07-23
Firefox HIGH 8.3
CVE-2019-9818

A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in t…

Fix: 60.7 / 67.0+
Fix from $1,950 2019-07-23
Firefox HIGH 8.1
CVE-2019-9821

A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable…

Fix: 67.0+
Fix from $1,950 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11713

A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable c…

Fix: 60.8.0 / 68.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11691

A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it h…

Fix: 60.7 / 67.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-11692

A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially ex…

Fix: 60.7.0 / 67.0+
Fix from $2,300 2019-07-23
Firefox CRITICAL 9.8
CVE-2019-9796

A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single re…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9790

A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed w…

Fix: after 66.0
Fix from $2,300 2019-04-26
Thunderbird CRITICAL 9.8
CVE-2018-18512

A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, a…

Fix: 65.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2018-18492EPSS 10%

A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. …

Fix: 60.4.0 / 64.0+
Fix from $2,300 2019-02-28