Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-14241 Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of… Firefox Mitigation only Fix from $2,3002026-06-30 MEDIUM 5.1 CVE-2026-6654 Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skip… Thin Vec No fix yet Fix from $1,6002026-04-20 CRITICAL 9.8 CVE-2026-5731 Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of th… Firefox Mitigation only Fix from $2,3002026-04-07 CRITICAL 9.8 CVE-2024-8389 Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox Mitigation only Fix from $2,3002024-09-03 CRITICAL 9.8 CVE-2024-8387 Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we p… Firefox Mitigation only Fix from $2,3002024-09-03 MEDIUM 6.1 CVE-2024-0953 When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi… Firefox No fix yet Fix from $1,6002024-02-05 MEDIUM 6.1 CVE-2023-42808 Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for traini… Common Voice No fix yet Fix from $1,6002023-10-04 HIGH 7.5 CVE-2023-25743 A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects … Firefox Focus Mitigation only Fix from $1,9502023-06-02 CRITICAL 9.8 CVE-2022-34485 Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs sh… Firefox Mitigation only Fix from $2,3002022-12-22 MEDIUM 6.1 CVE-2021-29979 Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s prim… Hubs Cloud Mitigation only Fix from $1,6002021-08-02 MEDIUM 6.5 CVE-2007-5967 A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval. Firefox Mitigation only Fix from $1,6002021-05-17 MEDIUM 6.1 CVE-2019-17001 A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-si… Firefox Mitigation only Fix from $1,6002020-01-08 MEDIUM 5.3 CVE-2018-12382 The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loade… Firefox No fix yet Fix from $1,6002018-10-18 HIGH 7.5 CVE-2017-7805 During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some case… Firefox Mitigation only Fix from $1,9502018-06-11 HIGH 7.8 CVE-2017-11695 Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attac… Network Security Services No fix yet Fix from $1,9502017-12-27 HIGH 7.8 CVE-2017-11696 Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent atta… Network Security Services No fix yet Fix from $1,9502017-12-27 HIGH 7.8 CVE-2017-11697 The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (fl… Network Security Services No fix yet Fix from $1,9502017-12-27 HIGH 7.8 CVE-2017-11698 Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent att… Network Security Services No fix yet Fix from $1,9502017-12-27 MEDIUM 6.1 CVE-2016-2803 Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers… Bugzilla No fix yet Fix from $1,6002017-04-12 HIGH 8.8 CVE-2016-2805 Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory … Firefox Mitigation only Fix from $1,9502016-04-30 MEDIUM 5.3 CVE-2016-1948 Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attack… Firefox Mitigation only Fix from $1,6002016-01-31 HIGH 8.8 CVE-2016-1945 The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other… Firefox Mitigation only Fix from $1,9502016-01-31 CRITICAL 9.8 CVE-2016-1944 The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of servic… Firefox No fix yet Fix from $2,3002016-01-31 HIGH 10.0 CVE-2015-4497EPSS 8% Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allow… Firefox Mitigation only Fix from $1,9502015-08-29 MEDIUM 6.8 CVE-2015-2727 Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chro… Firefox Mitigation only Fix from $1,6002015-07-06 HIGH 7.5 CVE-2015-0814 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory… Firefox Mitigation only Fix from $1,9502015-04-01 HIGH 7.5 CVE-2013-1741 Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have … Network Security Services Mitigation only Fix from $1,9502013-11-18 MEDIUM 5.8 CVE-2013-5606 The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return va… Network Security Services Mitigation only Fix from $1,6002013-11-18 MEDIUM 5.0 CVE-2012-5884 The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches… Bugzilla Mitigation only Fix from $1,6002012-11-16 HIGH 7.4 CVE-2012-5822 The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam… Zamboni No fix yet Fix from $1,9502012-11-04