Vulnerability index

Browse CVEs

57 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
0din Scanner CRITICAL 9.9
CVE-2026-41512

ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerab…

Fix: 1.4.1+
Fix from $2,300 2026-05-08
Firefox CRITICAL 9.8
CVE-2026-8094

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

Fix: 140.10.2+
Fix from $2,300 2026-05-07
Firefox CRITICAL 9.8
CVE-2025-14324

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thund…

Fix: 115.31.0 / 140.6.0+
Fix from $2,300 2025-12-09
Firefox HIGH 7.5
CVE-2025-11153

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.

Fix: 143.0.3+
Fix from $1,950 2025-09-30
Firefox HIGH 8.1
CVE-2025-8030

Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was …

Fix: 128.13.0 / 140.1.0+
Fix from $1,950 2025-07-22
Firefox HIGH 8.8
CVE-2025-1011

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution…

Fix: 128.7.0 / 135.0+
Fix from $1,950 2025-02-04
Firefox HIGH 8.8
CVE-2024-11697

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This co…

Fix: 128.5.0 / 133.0+
Fix from $1,950 2024-11-26
Firefox HIGH 8.8
CVE-2024-11699

Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we p…

Fix: 128.5 / 128.5.0+
Fix from $1,950 2024-11-26
Firefox HIGH 8.8
CVE-2024-7520

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129…

Fix: 128.1.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox CRITICAL 9.8
CVE-2024-6602

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thu…

Fix: 115.13 / 128.0+
Fix from $2,300 2024-07-09
Firefox MEDIUM 6.1
CVE-2024-2610

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulne…

Fix: 115.9.0 / 124.0+
Fix from $1,600 2024-03-19
Firefox HIGH 8.8
CVE-2024-0755

Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.7 / 122.0+
Fix from $1,950 2024-01-23
Firefox HIGH 8.8
CVE-2022-46874

A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This cou…

Fix: 102.6 / 108.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-22756

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable s…

Fix: 91.6 / 97.0+
Fix from $1,950 2022-12-22
Firefox HIGH 7.5
CVE-2014-8636EPSS 66%

The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Firefox HIGH 9.3
CVE-2014-1556

Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted W…

Fix: after 30.0
Fix from $1,950 2014-07-23
Firefox HIGH 9.3
CVE-2014-1557

The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does no…

Fix: after 30.0
Fix from $1,950 2014-07-23
Firefox CRITICAL 9.8
CVE-2013-6671EPSS 11%

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox HIGH 9.3
CVE-2013-1688

The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to …

Fix: after 21.0
Fix from $1,950 2013-06-26
Firefox HIGH 9.3
CVE-2013-0758EPSS 73%

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a…

Fix: 2.15 / 10.0.12+
Fix from $1,950 2013-01-13
Firefox HIGH 9.3
CVE-2013-0745

The AutoWrapperChanger class in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 1…

Fix: 2.15 / 17.0.2+
Fix from $1,950 2013-01-13
Firefox HIGH 7.5
CVE-2012-5836

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of…

Fix: 2.14 / 17.0+
Fix from $1,950 2012-11-21
Firefox MEDIUM 6.8
CVE-2012-5837

The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to condu…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Firefox HIGH 9.3
CVE-2012-3980

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allow…

Fix: after 14.0
Fix from $1,950 2012-08-29
Firefox HIGH 9.3
CVE-2011-3655

Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which…

Mitigation only
Fix from $1,950 2011-11-09
Firefox HIGH 9.3
CVE-2011-3232EPSS 5%

YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (…

Fix: after 6.0.2
Fix from $1,950 2011-09-29
Firefox HIGH 10.0
CVE-2011-0084

The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other version…

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Firefox HIGH 10.0
CVE-2011-2378EPSS 6%

The appendChild function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, SeaMonkey 2.x, and possibly other products does not properl…

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Firefox HIGH 10.0
CVE-2011-2984

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a t…

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Firefox HIGH 9.3
CVE-2010-2766EPSS 5%

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonke…

Fix: after 3.5.11
Fix from $1,950 2010-09-09