Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.4
CVE-2012-1950

The drag-and-drop implementation in Mozilla Firefox 4.x through 13.0 and Firefox ESR 10.x before 10.0.6 allows remote attackers to spoof the address …

Mitigation only
Fix from $1,600 2012-07-18
Firefox HIGH 9.3
CVE-2012-1939

jsinfer.cpp in Mozilla Firefox ESR 10.x before 10.0.5 and Thunderbird ESR 10.x before 10.0.5 does not properly determine data types, which allows rem…

Mitigation only
Fix from $1,950 2012-06-05
Firefox HIGH 7.2
CVE-2012-1942

The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain pri…

Mitigation only
Fix from $1,950 2012-06-05
Firefox MEDIUM 6.9
CVE-2012-1943

Untrusted search path vulnerability in Updater.exe in the Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Win…

Mitigation only
Fix from $1,600 2012-06-05
Firefox HIGH 7.5
CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to caus…

Mitigation only
Fix from $1,950 2012-02-11
Bugzilla MEDIUM 6.8
CVE-2011-3667

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, …

Mitigation only
Fix from $1,600 2012-01-02
Bugzilla MEDIUM 6.8
CVE-2011-3668

Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the aut…

No fix yet
Fix from $1,600 2012-01-02
Bugzilla MEDIUM 6.8
CVE-2011-3669

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the a…

No fix yet
Fix from $1,600 2012-01-02
Firefox HIGH 7.5
CVE-2011-3658EPSS 70%

The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, whi…

Mitigation only
Fix from $1,950 2011-12-21
Firefox HIGH 9.3
CVE-2011-3655

Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which…

Mitigation only
Fix from $1,950 2011-11-09
Firefox HIGH 10.0
CVE-2011-3651EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.0 allow remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,950 2011-11-09
Firefox HIGH 10.0
CVE-2011-2998EPSS 5%

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute…

Mitigation only
Fix from $1,950 2011-09-30
Firefox HIGH 10.0
CVE-2011-2996

Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (memory corru…

Mitigation only
Fix from $1,950 2011-09-29
Firefox HIGH 9.3
CVE-2011-2993

The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does n…

Mitigation only
Fix from $1,950 2011-08-18
Firefox MEDIUM 5.0
CVE-2011-2990

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other …

Mitigation only
Fix from $1,600 2011-08-18
Firefox HIGH 10.0
CVE-2011-2368

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2011-06-30
Firefox MEDIUM 6.4
CVE-2011-2367

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sen…

Mitigation only
Fix from $1,600 2011-06-30
Firefox HIGH 10.0
CVE-2011-0062

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote att…

Mitigation only
Fix from $1,950 2011-03-02
Bugzilla HIGH 7.5
CVE-2010-4568

Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not proper…

Mitigation only
Fix from $1,950 2011-01-28
Firefox HIGH 9.3
CVE-2010-3777EPSS 8%

Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2010-12-10
Firefox HIGH 10.0
CVE-2010-4508

The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impa…

Mitigation only
Fix from $1,950 2010-12-09
Firefox CRITICAL 9.8
CVE-2010-3765 KEVEPSS 83%

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.1…

Mitigation only
Fix from $2,300 2010-10-28
Firefox HIGH 9.3
CVE-2010-3175

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.11 and Thunderbird 3.1.x before 3.1.5 allow remote att…

Mitigation only
Fix from $1,950 2010-10-21
Firefox MEDIUM 5.8
CVE-2010-3171

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random …

No fix yet
Fix from $1,600 2010-09-15
Firefox MEDIUM 5.8
CVE-2010-3399

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a conte…

No fix yet
Fix from $1,600 2010-09-15
Firefox MEDIUM 6.8
CVE-2010-2762

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x bef…

Mitigation only
Fix from $1,600 2010-09-09
Bugzilla MEDIUM 6.5
CVE-2010-2757

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonat…

Mitigation only
Fix from $1,600 2010-08-16
Bugzilla MEDIUM 5.0
CVE-2010-2756

Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the …

Mitigation only
Fix from $1,600 2010-08-16
Bugzilla MEDIUM 5.0
CVE-2010-2758

Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whethe…

Mitigation only
Fix from $1,600 2010-08-16
Firefox HIGH 9.3
CVE-2010-1212

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a…

Mitigation only
Fix from $1,950 2010-07-30