Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
Firefox CRITICAL 9.8
CVE-2018-18500EPSS 13%

A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object…

Fix: 60.5 / 65.0+
Fix from $2,300 2019-02-05
Firefox HIGH 7.8
CVE-2016-9069

A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Fir…

Fix: 50.0+
Fix from $1,950 2018-10-18
Firefox HIGH 7.5
CVE-2018-5180

A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited…

Fix: 60.0+
Fix from $1,950 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5128

A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potenti…

Fix: 59.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5092

A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread …

Fix: after 57.0.4
Fix from $2,300 2018-06-11
Firefox HIGH 7.5
CVE-2018-5100EPSS 5%

A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. Thi…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5101

A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some case…

Mitigation only
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-7806

A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially ex…

Fix: 55.0+
Fix from $1,950 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7756

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially e…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7757

A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5403

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after…

Fix: 52.0+
Fix from $2,300 2018-06-11
Firefox HIGH 7.5
CVE-2017-5411

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be free…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox HIGH 8.1
CVE-2016-9896

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Fi…

Fix: 50.1.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5379

Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51.

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9068

A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox <…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-9067

Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5287

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefo…

Fix: 49.0.2+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5281EPSS 5%

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows re…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5280EPSS 5%

Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 4…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5277

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5276

Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x b…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5274

Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thun…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox HIGH 8.8
CVE-2016-5264

Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 4…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-5259

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remo…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-5255

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbi…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox CRITICAL 9.8
CVE-2016-5254

Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attack…

Fix: after 47.0.1
Fix from $2,300 2016-08-05
Firefox HIGH 10.0
CVE-2014-1563EPSS 6%

Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thun…

Fix: after 31.1.0
Fix from $1,950 2014-09-03
Firefox CRITICAL 9.8
CVE-2014-1532

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x…

Fix: 24.5 / 29.0+
Fix from $2,300 2014-04-30
Firefox HIGH 8.8
CVE-2014-1531EPSS 6%

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.…

Fix: 24.5 / 29.0+
Fix from $1,950 2014-04-30