Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Firefox CRITICAL 9.8
CVE-2026-16410

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.1
CVE-2026-16392

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16355

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thun…

Fix: 115.38.0 / 140.13.0+
Fix from $2,300 2026-07-21
Firefox CRITICAL 9.8
CVE-2026-16363

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Th…

Fix: 140.13.0 / 153.0+
Fix from $2,300 2026-07-21
Firefox MEDIUM 5.4
CVE-2026-12298

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Fix: 140.12.0 / 152.0+
Fix from $1,600 2026-06-16
Firefox MEDIUM 5.4
CVE-2026-12299

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbir…

Fix: 115.37.0 / 140.12.0+
Fix from $1,600 2026-06-16
Firefox HIGH 8.8
CVE-2026-8389

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

Fix: 150.0.3+
Fix from $1,950 2026-05-12
Firefox CRITICAL 9.8
CVE-2026-4702

JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbi…

Fix: 140.9.0 / 149.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-4698

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thund…

Fix: 115.34.0 / 140.9.0+
Fix from $2,300 2026-03-24
Firefox CRITICAL 9.8
CVE-2026-2796

JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

Fix: 148.0+
Fix from $2,300 2026-02-24
Firefox HIGH 7.5
CVE-2026-2783

Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 148, Firefox ESR 14…

Fix: 140.8.0 / 148.0+
Fix from $1,950 2026-02-24
Firefox CRITICAL 9.8
CVE-2025-14330

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…

Fix: 140.6.0 / 146.0+
Fix from $2,300 2025-12-09
Firefox HIGH 7.3
CVE-2025-14325

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thun…

Fix: 140.6.0 / 146.0+
Fix from $1,950 2025-12-09
Firefox HIGH 7.5
CVE-2024-7652

An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption…

Fix: 115.13.0 / 128.0+
Fix from $1,950 2024-09-06
Firefox CRITICAL 9.8
CVE-2024-8381

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This v…

Fix: 115.15 / 128.2+
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8385

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulner…

Fix: 128.2 / 130.0+
Fix from $2,300 2024-09-03
Firefox HIGH 8.8
CVE-2024-7520

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129…

Fix: 128.1.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2023-28162

While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploita…

Fix: 102.9 / 111.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2021-23954

Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a …

Fix: 78.7 / 85.0+
Fix from $1,950 2021-02-26
Firefox HIGH 8.8
CVE-2020-15656

JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions…

Fix: 78.1 / 79.0+
Fix from $1,950 2020-08-10
Firefox HIGH 8.8
CVE-2019-17026 KEVEPSS 47%

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in …

Fix: 68.4.1 / 72.0.1+
Fix from $1,950 2020-03-02
Firefox HIGH 8.8
CVE-2019-17017

Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort tha…

Fix: 68.4 / 72.0+
Fix from $1,950 2020-01-08
Firefox MEDIUM 6.5
CVE-2019-11750

A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox …

Fix: 68.1.0 / 69.0+
Fix from $1,600 2019-09-27
Firefox CRITICAL 9.8
CVE-2019-9819

A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. Thi…

Fix: 60.7 / 67.0+
Fix from $2,300 2019-07-23
Firefox MEDIUM 5.9
CVE-2019-9816EPSS 6%

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of s…

Fix: 60.7 / 67.0+
Fix from $1,600 2019-07-23
Firefox HIGH 8.8
CVE-2019-11707 KEVEPSS 38%

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We…

Fix: 60.7.1 / 60.7.2+
Fix from $1,950 2019-07-23
Thunderbird HIGH 7.5
CVE-2019-11706EPSS 10%

A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email message…

Fix: 60.7.1+
Fix from $1,950 2019-07-23
Firefox HIGH 8.8
CVE-2019-9813EPSS 7%

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. …

Fix: 60.6.1 / 66.0.1+
Fix from $1,950 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9795

A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a pote…

Fix: 60.6 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9791EPSS 20%

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonM…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26