Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Firefox HIGH 8.8
CVE-2022-46873

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise prote…

Fix: 108.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-40958

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite c…

Fix: 102.3 / 105.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 5.3
CVE-2021-29955

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have …

Fix: 78.9 / 87.0+
Fix from $1,600 2021-06-24
Firefox HIGH 8.8
CVE-2021-24002

When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed a…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.3
CVE-2019-9811

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser fea…

Fix: 60.8 / 68.0+
Fix from $1,950 2019-07-23
Firefox MEDIUM 5.3
CVE-2019-11718

Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page with…

Fix: 68.0+
Fix from $1,600 2019-07-23
Firefox CRITICAL 9.8
CVE-2017-7788

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S…

Fix: 55.0+
Fix from $2,300 2018-06-11
Firefox MEDIUM 6.4
CVE-2012-4196

Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before …

Fix: 2.13.2 / 10.0.10+
Fix from $1,600 2012-10-29