Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Firefox CRITICAL 9.8
CVE-2026-16353

Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunder…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox MEDIUM 5.3
CVE-2026-12329

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Fix: 140.12.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.3
CVE-2026-6778

Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Fix: 150.0+
Fix from $1,600 2026-04-21
Firefox MEDIUM 6.5
CVE-2025-8033

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability wa…

Fix: 115.26.0 / 128.13.0+
Fix from $1,600 2025-07-22
Firefox MEDIUM 6.5
CVE-2024-11706

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling m…

Fix: 133.0+
Fix from $1,600 2024-11-26
Firefox CRITICAL 9.1
CVE-2024-11705

`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred…

Fix: 133.0+
Fix from $2,300 2024-11-26
Firefox HIGH 7.5
CVE-2024-7652

An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption…

Fix: 115.13.0 / 128.0+
Fix from $1,950 2024-09-06
Firefox HIGH 7.5
CVE-2024-3858

It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.

Fix: 125.0+
Fix from $1,950 2024-04-16
Firefox MEDIUM 6.5
CVE-2023-37456

The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

Fix: 115+
Fix from $1,600 2023-07-12
Firefox HIGH 8.8
CVE-2023-29539

When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. T…

Fix: 102.10 / 112.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2022-42928

Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption an…

Fix: 102.4 / 106.0+
Fix from $1,950 2022-12-22
Network Security Services MEDIUM 6.5
CVE-2018-18508

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a…

Fix: 2.14.0 / 3.36.7+
Fix from $1,600 2020-10-22
Thunderbird MEDIUM 6.5
CVE-2020-6795

When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to a…

Fix: 68.5.0+
Fix from $1,600 2020-03-02
Thunderbird HIGH 7.5
CVE-2018-18513

A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service …

Fix: 60.5.0+
Fix from $1,950 2019-04-26
Firefox HIGH 7.5
CVE-2017-5416

In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vuln…

Fix: 52.0+
Fix from $1,950 2018-06-11
Network Security Services HIGH 7.5
CVE-2017-7502

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re…

Patch available
Fix from $1,950 2017-05-30