Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
CRITICAL 9.8 CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunder… Firefox 115.38.0 / 140.13.0+ Fix from $2,3002026-07-21 MEDIUM 5.3 CVE-2026-12329 Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. Firefox 140.12.0+ Fix from $1,6002026-06-16 MEDIUM 5.3 CVE-2026-6778 Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2025-8033 The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability wa… Firefox 115.26.0 / 128.13.0+ Fix from $1,6002025-07-22 MEDIUM 6.5 CVE-2024-11706 A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling m… Firefox 133.0+ Fix from $1,6002024-11-26 CRITICAL 9.1 CVE-2024-11705 `NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred… Firefox 133.0+ Fix from $2,3002024-11-26 HIGH 7.5 CVE-2024-7652 An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption… Firefox 115.13.0 / 128.0+ Fix from $1,9502024-09-06 HIGH 7.5 CVE-2024-3858 It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125. Firefox 125.0+ Fix from $1,9502024-04-16 MEDIUM 6.5 CVE-2023-37456 The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115. Firefox 115+ Fix from $1,6002023-07-12 HIGH 8.8 CVE-2023-29539 When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. T… Firefox 102.10 / 112.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2022-42928 Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption an… Firefox 102.4 / 106.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2018-18508 In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a… Network Security Services 2.14.0 / 3.36.7+ Fix from $1,6002020-10-22 MEDIUM 6.5 CVE-2020-6795 When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to a… Thunderbird 68.5.0+ Fix from $1,6002020-03-02 HIGH 7.5 CVE-2018-18513 A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service … Thunderbird 60.5.0+ Fix from $1,9502019-04-26 HIGH 7.5 CVE-2017-5416 In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vuln… Firefox 52.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re… Network Security Services Patch available Fix from $1,9502017-05-30