Vulnerability index

Browse CVEs

81 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
MEDIUM 6.1 CVE-2018-5124 Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1. Firefox 58.0.1+ Fix from $1,6002019-04-26 MEDIUM 6.1 CVE-2018-5164 Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This co… Firefox 60.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2018-5143 URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a… Firefox 59.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-7834 A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy includi… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-7839 Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScr… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-7840 JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting ex… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-7799 JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is n… Firefox 55.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-5458 When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socia… Firefox 53.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-5393 The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow mal… Firefox 51.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2016-9903 Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to b… Firefox 50.1+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2016-10547 Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape … Nunjucks after 2.4.2 Fix from $1,6002018-05-31 MEDIUM 6.1 CVE-2016-2803 Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers… Bugzilla No fix yet Fix from $1,6002017-04-12 MEDIUM 6.1 CVE-2016-5262 Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRA… Firefox after 47.0.1 Fix from $1,6002016-08-05 MEDIUM 6.1 CVE-2016-2833 Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attacker… Firefox after 46.0.1 Fix from $1,6002016-06-13 MEDIUM 6.1 CVE-2016-1941 The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickj… Firefox after 43.0.4 Fix from $1,6002016-01-31 MEDIUM 6.1 CVE-2016-1937 The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that trigge… Firefox after 43.0.4 Fix from $1,6002016-01-31 MEDIUM 6.1 CVE-2015-8510 Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows us… Firefox Os after 2.2 Fix from $1,6002016-01-09 MEDIUM 6.1 CVE-2014-1530 The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows r… Firefox 24.5 / 29.0+ Fix from $1,6002014-04-30 MEDIUM 6.8 CVE-2012-5837 The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to condu… Firefox after 16.0.2 Fix from $1,6002012-11-21 CRITICAL 9.8 CVE-2007-4039 Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting atta… Mozilla Mitigation only Fix from $2,3002007-07-27 MEDIUM 6.8 CVE-2007-0780 browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child wind… Firefox 1.0.8 / 1.5.0.10+ Fix from $1,6002007-02-26