Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.7
CVE-2025-0241

When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in…

Fix: 128.6.0 / 134.0+
Fix from $1,950 2025-01-07
Firefox MEDIUM 6.5
CVE-2025-0242EPSS 13%

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of…

Fix: 128.6.0 / 134.0+
Fix from $1,600 2025-01-07
Firefox MEDIUM 5.4
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the prin…

Fix: 128.6.0 / 134.0+
Fix from $1,600 2025-01-07
Firefox MEDIUM 5.3
CVE-2025-0238

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vuln…

Fix: 115.19.0 / 128.6+
Fix from $1,600 2025-01-07
Firefox MEDIUM 5.1
CVE-2025-0243

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory co…

Fix: 128.6.0 / 133.0+
Fix from $1,600 2025-01-07
Firefox MEDIUM 5.4
CVE-2024-53975

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure…

Fix: 133.0+
Fix from $1,600 2024-11-26
Firefox MEDIUM 5.4
CVE-2024-53976

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL wa…

Fix: 133.0+
Fix from $1,600 2024-11-26
Firefox MEDIUM 6.5
CVE-2024-11706

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling m…

Fix: 133.0+
Fix from $1,600 2024-11-26
Firefox MEDIUM 6.5
CVE-2024-11708

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefo…

Fix: 133.0+
Fix from $1,600 2024-11-26
Firefox CRITICAL 9.8
CVE-2024-11698

A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was op…

Fix: 128.5.0 / 133.0+
Fix from $2,300 2024-11-26
Firefox CRITICAL 9.8
CVE-2024-11704

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symme…

Fix: 128.7.0 / 133.0+
Fix from $2,300 2024-11-26
Firefox CRITICAL 9.1
CVE-2024-11705

`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred…

Fix: 133.0+
Fix from $2,300 2024-11-26
Firefox HIGH 8.8
CVE-2024-11697

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This co…

Fix: 128.5.0 / 133.0+
Fix from $1,950 2024-11-26
Firefox HIGH 8.8
CVE-2024-11699

Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we p…

Fix: 128.5 / 128.5.0+
Fix from $1,950 2024-11-26
Firefox HIGH 8.1
CVE-2024-11700

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the …

Fix: 133.0+
Fix from $1,950 2024-11-26
Firefox HIGH 7.5
CVE-2024-11702

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboa…

Fix: 133.0+
Fix from $1,950 2024-11-26
Firefox MEDIUM 5.7
CVE-2024-11703

On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects…

Fix: 133.0+
Fix from $1,600 2024-11-26
Firefox MEDIUM 5.4
CVE-2024-11695

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing att…

Fix: 128.5.0 / 133.0+
Fix from $1,600 2024-11-26
Firefox MEDIUM 5.4
CVE-2024-11696

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, trigger…

Fix: 128.5.0 / 133.0+
Fix from $1,600 2024-11-26
Firefox CRITICAL 9.8
CVE-2024-11693

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other …

Fix: 128.5.0 / 133.0+
Fix from $2,300 2024-11-26
Firefox HIGH 8.8
CVE-2024-11691

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's G…

Fix: 115.18.0 / 128.5.0+
Fix from $1,950 2024-11-26
Firefox MEDIUM 6.1
CVE-2024-11694

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shi…

Fix: 115.8.0 / 115.18.0+
Fix from $1,600 2024-11-26
Sccache HIGH 7.8
CVE-2023-1521

On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library pass…

Fix: 0.4.0+
Fix from $1,950 2024-11-26
Nunjucks MEDIUM 6.1
CVE-2023-2142

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If ther…

Fix: 3.2.4+
Fix from $1,600 2024-11-26
Convict HIGH 8.4
CVE-2023-0163

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker …

Fix: 6.2.4+
Fix from $1,950 2024-11-26
Firefox MEDIUM 6.5
CVE-2024-10941

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Fire…

Fix: 126.0+
Fix from $1,600 2024-11-06
Firefox HIGH 8.8
CVE-2024-10467

Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we p…

Fix: 128.4.0 / 132.0+
Fix from $1,950 2024-10-29
Firefox HIGH 7.5
CVE-2024-10466

By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vul…

Fix: 128.4.0 / 132.0+
Fix from $1,950 2024-10-29
Firefox MEDIUM 6.5
CVE-2024-10463

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < …

Fix: 115.17.0 / 128.4.0+
Fix from $1,600 2024-10-29
Firefox MEDIUM 6.5
CVE-2024-10464

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by int…

Fix: 128.4.0 / 132.0+
Fix from $1,600 2024-10-29