Vulnerability index

Browse CVEs

230 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Network Security Services CRITICAL 9.8
CVE-2017-5461

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows rem…

Fix: 3.21.4 / 3.28.4+
Fix from $2,300 2017-05-11
Firefox CRITICAL 9.8
CVE-2016-5270

Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox HIGH 9.3
CVE-2014-1525

The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection fo…

Fix: 2.26 / 29.0+
Fix from $1,950 2014-04-30
Firefox MEDIUM 6.5
CVE-2014-1523

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMon…

Fix: 24.5 / 29.0+
Fix from $1,600 2014-04-30
Firefox CRITICAL 9.8
CVE-2014-1514EPSS 6%

vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not vali…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox HIGH 8.8
CVE-2014-1513EPSS 6%

TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not preven…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox HIGH 10.0
CVE-2014-1478EPSS 7%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a…

Fix: 2.24 / 27.0+
Fix from $1,950 2014-02-06
Firefox HIGH 8.8
CVE-2014-1482EPSS 6%

RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent acc…

Fix: 24.3 / 27.0+
Fix from $1,950 2014-02-06
Firefox HIGH 10.0
CVE-2013-5610EPSS 7%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a…

Fix: 2.23 / 26.0+
Fix from $1,950 2013-12-11
Firefox HIGH 9.3
CVE-2013-0782EPSS 5%

Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thund…

Fix: 17.0.3 / 19.0+
Fix from $1,950 2013-02-19
Firefox HIGH 9.3
CVE-2013-0768EPSS 8%

Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, T…

Fix: 2.15 / 17.0.2+
Fix from $1,950 2013-01-13
Firefox HIGH 9.3
CVE-2013-0771EPSS 5%

Heap-based buffer overflow in the gfxTextRun::ShrinkToLigatureBoundaries function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thu…

Fix: 2.15 / 10.0.12+
Fix from $1,950 2013-01-13
Firefox HIGH 9.3
CVE-2012-5829EPSS 8%

Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird befor…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-5839EPSS 7%

Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4202EPSS 11%

Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbi…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4191

The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and…

Fix: 2.13.1 / 16.0.1+
Fix from $1,950 2012-10-12
Firefox HIGH 10.0
CVE-2012-3957EPSS 8%

Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird be…

Fix: 2.12 / 10.0.7+
Fix from $1,950 2012-08-29
Firefox HIGH 9.3
CVE-2012-3967

The WebGL implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7,…

Fix: 2.12 / 10.0.7+
Fix from $1,950 2012-08-29
Firefox HIGH 10.0
CVE-2009-2466EPSS 7%

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and ap…

Fix: 3.0.12+
Fix from $1,950 2009-07-22
Firefox HIGH 9.3
CVE-2009-0733EPSS 6%

Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta…

Fix: 2.9.2+
Fix from $1,950 2009-03-23