Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
CRITICAL 9.8 CVE-2020-15684 Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 82.0+ Fix from $2,3002020-10-22 HIGH 8.8 CVE-2020-15669 When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-fr… Firefox Esr 68.12+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15670 Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we pres… Firefox 78.2 / 80.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15673 Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption an… Firefox 78.3 / 81.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15675 When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnera… Firefox 81.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15678 When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs be… Firefox 78.3 / 81.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-12416 A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption… Firefox 78.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12419 When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free conditi… Firefox 68.10 / 68.10.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12420 When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potenti… Firefox 68.10.0 / 78.0+ Fix from $1,9502020-07-09 MEDIUM 5.3 CVE-2020-12405 When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerabili… Firefox 68.9.0 / 77.0+ Fix from $1,6002020-07-09 HIGH 8.1 CVE-2020-12387 A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. T… Firefox 68.8.0 / 76.0+ Fix from $1,9502020-05-26 HIGH 8.1 CVE-2020-6819 KEV Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th… Firefox 68.6.1 / 68.7.0+ Fix from $1,9502020-04-24 HIGH 8.8 CVE-2020-6805 When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially explo… Firefox 68.6.0 / 74.0+ Fix from $1,9502020-03-25 HIGH 8.8 CVE-2020-6807 When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was d… Firefox 68.6.0 / 74.0+ Fix from $1,9502020-03-25 HIGH 8.8 CVE-2019-17013 Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 71.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-17008 When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerabili… Firefox 68.3 / 71.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11756 Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability… Firefox 71.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11757 When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulte… Firefox 68.2 / 70.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11752 It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentia… Firefox 60.9.0 / 68.1.0+ Fix from $1,9502019-09-27 HIGH 8.8 CVE-2019-11746 A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exp… Firefox 60.9.0 / 68.1.0+ Fix from $1,9502019-09-27 CRITICAL 9.8 CVE-2019-9820 A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable c… Firefox 60.7 / 60.7.0+ Fix from $2,3002019-07-23 HIGH 8.3 CVE-2019-9818 A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in t… Firefox 60.7 / 67.0+ Fix from $1,9502019-07-23 HIGH 8.1 CVE-2019-9821 A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable… Firefox 67.0+ Fix from $1,9502019-07-23 CRITICAL 9.8 CVE-2019-11713 A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable c… Firefox 60.8.0 / 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11691 A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it h… Firefox 60.7 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11692 A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially ex… Firefox 60.7.0 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-9796 A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single re… Firefox 60.6.0 / 66.0+ Fix from $2,3002019-04-26 CRITICAL 9.8 CVE-2019-9790 A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed w… Firefox after 66.0 Fix from $2,3002019-04-26 CRITICAL 9.8 CVE-2018-18512 A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, a… Thunderbird 65.0+ Fix from $2,3002019-04-26 CRITICAL 9.8 CVE-2018-18492EPSS 10% A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. … Firefox 60.4.0 / 64.0+ Fix from $2,3002019-02-28