Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Firefox MEDIUM 5.5
CVE-2022-36314

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from…

Fix: 102.1 / 103.0+
Fix from $1,600 2022-12-22
Firefox HIGH 7.0
CVE-2022-22736

If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for syst…

Fix: 96.0+
Fix from $1,950 2022-12-22
Thunderbird HIGH 7.8
CVE-2021-29949

When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that is…

Fix: 78.9.1+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2020-15663

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system…

Fix: 68.12 / 78.2+
Fix from $1,950 2020-10-01
Firefox HIGH 7.8
CVE-2020-15657

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placi…

Fix: 78.1 / 79.0+
Fix from $1,950 2020-08-10
Firefox HIGH 7.8
CVE-2020-12423

When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox m…

Fix: 78.0+
Fix from $1,950 2020-07-09
Firefox HIGH 7.8
CVE-2017-7836

The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allow…

Fix: after 56.0.2
Fix from $1,950 2018-06-11