Vulnerability index

Browse CVEs

81 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Firefox MEDIUM 6.1
CVE-2018-5124

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

Fix: 58.0.1+
Fix from $1,600 2019-04-26
Firefox MEDIUM 6.1
CVE-2018-5164

Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This co…

Fix: 60.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2018-5143

URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-7834

A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy includi…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-7839

Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScr…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-7840

JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting ex…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-7799

JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is n…

Fix: 55.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-5458

When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socia…

Fix: 53.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-5393

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow mal…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2016-9903

Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to b…

Fix: 50.1+
Fix from $1,600 2018-06-11
Nunjucks MEDIUM 6.1
CVE-2016-10547

Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape …

Fix: after 2.4.2
Fix from $1,600 2018-05-31
Bugzilla MEDIUM 6.1
CVE-2016-2803

Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers…

No fix yet
Fix from $1,600 2017-04-12
Firefox MEDIUM 6.1
CVE-2016-5262

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRA…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox MEDIUM 6.1
CVE-2016-2833

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attacker…

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Firefox MEDIUM 6.1
CVE-2016-1941

The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickj…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 6.1
CVE-2016-1937

The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that trigge…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox Os MEDIUM 6.1
CVE-2015-8510

Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows us…

Fix: after 2.2
Fix from $1,600 2016-01-09
Firefox MEDIUM 6.1
CVE-2014-1530

The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows r…

Fix: 24.5 / 29.0+
Fix from $1,600 2014-04-30
Firefox MEDIUM 6.8
CVE-2012-5837

The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to condu…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Mozilla CRITICAL 9.8
CVE-2007-4039

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting atta…

Mitigation only
Fix from $2,300 2007-07-27
Firefox MEDIUM 6.8
CVE-2007-0780

browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child wind…

Fix: 1.0.8 / 1.5.0.10+
Fix from $1,600 2007-02-26