Vulnerability index

Browse CVEs

259 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use After FreeCWE-416 × clear
CRITICAL 9.8 CVE-2018-18500EPSS 13% A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object… Firefox 60.5 / 65.0+ Fix from $2,3002019-02-05 HIGH 7.8 CVE-2016-9069 A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Fir… Firefox 50.0+ Fix from $1,9502018-10-18 HIGH 7.5 CVE-2018-5180 A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited… Firefox 60.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2018-5128 A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potenti… Firefox 59.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2018-5092 A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread … Firefox after 57.0.4 Fix from $2,3002018-06-11 HIGH 7.5 CVE-2018-5100EPSS 5% A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. Thi… Firefox after 57.0.4 Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5101 A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This… Firefox after 57.0.4 Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7805 During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some case… Firefox Mitigation only Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7806 A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially ex… Firefox 55.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2017-7756 A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially e… Firefox 52.2.0 / 54.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7757 A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results… Firefox 52.2.0 / 54.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5403 When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after… Firefox 52.0+ Fix from $2,3002018-06-11 HIGH 7.5 CVE-2017-5411 A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be free… Firefox 52.0+ Fix from $1,9502018-06-11 HIGH 8.1 CVE-2016-9896 Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Fi… Firefox 50.1.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5379 Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51. Firefox 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9068 A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox <… Firefox 50.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2016-9067 Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50. Firefox 50.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2016-5287 A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefo… Firefox 49.0.2+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5281EPSS 5% Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows re… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5280EPSS 5% Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 4… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5277 Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5276 Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x b… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5274 Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thun… Firefox after 48.0.2 Fix from $2,3002016-09-22 HIGH 8.8 CVE-2016-5264 Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 4… Firefox after 47.0.1 Fix from $1,9502016-08-05 HIGH 8.8 CVE-2016-5259 Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remo… Firefox after 47.0.1 Fix from $1,9502016-08-05 HIGH 8.8 CVE-2016-5255 Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbi… Firefox after 47.0.1 Fix from $1,9502016-08-05 CRITICAL 9.8 CVE-2016-5254 Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attack… Firefox after 47.0.1 Fix from $2,3002016-08-05 HIGH 10.0 CVE-2014-1563EPSS 6% Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thun… Firefox after 31.1.0 Fix from $1,9502014-09-03 CRITICAL 9.8 CVE-2014-1532 Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x… Firefox 24.5 / 29.0+ Fix from $2,3002014-04-30 HIGH 8.8 CVE-2014-1531EPSS 6% Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.… Firefox 24.5 / 29.0+ Fix from $1,9502014-04-30