Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.8
CVE-2010-1215

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrap…

Mitigation only
Fix from $1,600 2010-07-30
Firefox HIGH 10.0
CVE-2010-2755

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows rem…

Mitigation only
Fix from $1,950 2010-07-30
Bugzilla MEDIUM 5.0
CVE-2010-1204

Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive t…

Mitigation only
Fix from $1,600 2010-06-28
Firefox HIGH 9.3
CVE-2010-1203

The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application cr…

Mitigation only
Fix from $1,950 2010-06-24
Firefox HIGH 10.0
CVE-2010-1988EPSS 6%

Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or poss…

No fix yet
Fix from $1,950 2010-05-20
Firefox MEDIUM 5.0
CVE-2010-1986

Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScrip…

No fix yet
Fix from $1,600 2010-05-20
Firefox MEDIUM 5.0
CVE-2010-1987

Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application…

No fix yet
Fix from $1,600 2010-05-20
Firefox HIGH 10.0
CVE-2010-1122

Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and applicat…

Mitigation only
Fix from $1,950 2010-03-25
Firefox HIGH 10.0
CVE-2010-1121EPSS 6%

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote …

Mitigation only
Fix from $1,950 2010-03-25
Firefox HIGH 9.3
CVE-2010-0164EPSS 6%

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.…

No fix yet
Fix from $1,950 2010-03-25
Firefox HIGH 9.3
CVE-2010-0165

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attacke…

Mitigation only
Fix from $1,950 2010-03-25
Firefox MEDIUM 5.1
CVE-2010-0166EPSS 7%

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when …

Mitigation only
Fix from $1,600 2010-03-25
Firefox HIGH 9.3
CVE-2010-1028EPSS 9%

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.…

Mitigation only
Fix from $1,950 2010-03-19
Firefox HIGH 10.0
CVE-2009-1571EPSS 6%

Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonke…

Mitigation only
Fix from $1,950 2010-02-22
Seamonkey MEDIUM 5.0
CVE-2009-4629

Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or A…

Mitigation only
Fix from $1,600 2010-01-29
Firefox MEDIUM 5.0
CVE-2009-4630

Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML d…

Mitigation only
Fix from $1,600 2010-01-29
Firefox MEDIUM 5.8
CVE-2009-4129

Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in…

Mitigation only
Fix from $1,600 2009-12-14
Firefox MEDIUM 5.8
CVE-2009-4130

Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the o…

Mitigation only
Fix from $1,600 2009-12-14
Firefox HIGH 10.0
CVE-2009-3383

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2009-10-29
Firefox MEDIUM 5.0
CVE-2009-3370

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverag…

Mitigation only
Fix from $1,600 2009-10-29
Firefox HIGH 10.0
CVE-2009-3069

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory co…

Mitigation only
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3073

Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory…

Mitigation only
Fix from $1,950 2009-09-10
Firefox MEDIUM 5.0
CVE-2009-2975

Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement s…

No fix yet
Fix from $1,600 2009-08-27
Firefox MEDIUM 5.0
CVE-2009-2953

Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a lo…

Mitigation only
Fix from $1,600 2009-08-24
Firefox HIGH 7.8
CVE-2009-2479EPSS 12%

Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via …

No fix yet
Fix from $1,950 2009-07-16
Firefox MEDIUM 5.0
CVE-2009-2478EPSS 8%

Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, re…

No fix yet
Fix from $1,600 2009-07-16
Firefox MEDIUM 5.0
CVE-2009-1827

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Ra…

No fix yet
Fix from $1,600 2009-05-29
Firefox MEDIUM 5.0
CVE-2009-1828EPSS 9%

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN el…

No fix yet
Fix from $1,600 2009-05-29
Firefox HIGH 9.3
CVE-2009-1597

Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline …

No fix yet
Fix from $1,950 2009-05-11
Firefox HIGH 9.3
CVE-2009-1313EPSS 8%

The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,950 2009-04-30