Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
Vpn MEDIUM 5.5
CVE-2023-4104

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN se…

Fix: 2.16.1+
Fix from $1,600 2023-09-11
Firefox MEDIUM 6.5
CVE-2023-3482

When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of '…

Fix: 115.0+
Fix from $1,600 2023-07-05
Firefox MEDIUM 6.5
CVE-2022-45410

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of…

Fix: 102.5 / 107.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2021-23975

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function …

Fix: 86.0+
Fix from $1,600 2021-02-26
Firefox CRITICAL 9.8
CVE-2020-6823

A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise return…

Fix: 75.0+
Fix from $2,300 2020-04-24
Firefox MEDIUM 5.4
CVE-2019-11761

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from expos…

Fix: 68.2 / 70.0+
Fix from $1,600 2020-01-08
Firefox MEDIUM 6.5
CVE-2019-11700

A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompt…

Fix: 67.0+
Fix from $1,600 2019-07-23
Firefox MEDIUM 6.5
CVE-2019-11702

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Ex…

Fix: 67.0.2+
Fix from $1,600 2019-07-23
Firefox HIGH 7.5
CVE-2018-5135

WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this sh…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5113

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properl…

Fix: after 57.0.4
Fix from $1,950 2018-06-11