Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
HIGH 8.8 CVE-2022-45409 The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, lead… Firefox 102.5 / 107.0+ Fix from $1,9502022-12-22 HIGH 7.5 CVE-2022-45407 If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exp… Firefox 107.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-45405 Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable cr… Firefox 102.5 / 107.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-40960 Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash… Firefox 102.3 / 105.0+ Fix from $1,6002022-12-22 HIGH 7.5 CVE-2022-38476 A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock prot… Firefox Esr 102.2+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-34484 The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and… Firefox 91.11 / 102.0+ Fix from $1,9502022-12-22 CRITICAL 9.8 CVE-2022-34470 Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR… Firefox 91.11 / 102.0+ Fix from $2,3002022-12-22 CRITICAL 9.8 CVE-2022-31747 Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox … Firefox 91.10 / 101+ Fix from $2,3002022-12-22 MEDIUM 6.5 CVE-2022-28282 By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution a… Firefox 91.8 / 99.0+ Fix from $1,6002022-12-22 CRITICAL 9.6 CVE-2022-26486 KEV An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in th… Firefox 91.6.1 / 91.6.2+ Fix from $2,3002022-12-22 HIGH 8.8 CVE-2022-26485 KEVEPSS 14% Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing thi… Firefox 91.6.1 / 91.6.2+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-26385 In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a po… Firefox 98.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2022-26381 An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerabili… Firefox 91.7 / 98.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-22740 Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a pote… Firefox 91.5 / 96.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-1097 <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use… Firefox 91.8 / 99.0+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2022-1196 After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. Th… Firefox Esr 91.8+ Fix from $1,6002022-12-22 MEDIUM 6.5 CVE-2021-4128 When transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentially exp… Firefox 95.0+ Fix from $1,6002022-12-22 HIGH 8.8 CVE-2021-43535 A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially e… Firefox 91.3.0 / 93.0+ Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-43539 Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those liv… Firefox 91.4.0 / 95.0+ Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-38504 When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory co… Firefox 91.3.0 / 94.0+ Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-38496 During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploi… Firefox 78.15 / 91.2+ Fix from $1,9502021-11-03 HIGH 7.5 CVE-2021-38498 During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially … Firefox 91.2 / 93.0+ Fix from $1,9502021-11-03 HIGH 8.8 CVE-2021-29985 A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects … Firefox 78.13.0 / 91.0+ Fix from $1,9502021-08-17 HIGH 8.8 CVE-2021-29970 A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered … Firefox 78.12 / 90.0+ Fix from $1,9502021-08-05 HIGH 8.8 CVE-2021-29972 A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may ha… Firefox 90.0+ Fix from $1,9502021-08-05 CRITICAL 9.8 CVE-2020-26972 The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a d… Firefox 84.0+ Fix from $2,3002021-01-07 HIGH 8.8 CVE-2020-26959 During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, an… Firefox 78.5 / 83.0+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26960 If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-… Firefox 78.5 / 83.0+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26950EPSS 42% In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. Thi… Firefox 78.4.1 / 78.4.2+ Fix from $1,9502020-12-09 CRITICAL 9.8 CVE-2020-15683 Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence o… Firefox 78.4 / 82.0+ Fix from $2,3002020-10-22