Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2024-8384

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. Thi…

Fix: 115.15 / 128.2+
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8385

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulner…

Fix: 128.2 / 130.0+
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8387

Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we p…

Mitigation only
Fix from $2,300 2024-09-03
Firefox HIGH 8.8
CVE-2024-8382

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that …

Fix: 115.15 / 128.2+
Fix from $1,950 2024-09-03
Firefox HIGH 7.5
CVE-2024-8383

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support…

Fix: 115.15 / 128.2+
Fix from $1,950 2024-09-03
Firefox MEDIUM 6.1
CVE-2024-8386

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofin…

Fix: 128.2 / 130.0+
Fix from $1,600 2024-09-03
Firefox MEDIUM 5.3
CVE-2024-8388

Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mo…

Fix: 130.0+
Fix from $1,600 2024-09-03
Firefox Mobile MEDIUM 6.1
CVE-2024-43111

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for…

Fix: 129+
Fix from $1,600 2024-08-06
Firefox Mobile MEDIUM 6.1
CVE-2024-43112

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

Fix: 129+
Fix from $1,600 2024-08-06
Firefox Mobile MEDIUM 6.1
CVE-2024-43113

The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects Firefox for iOS < 129.

Fix: 129+
Fix from $1,600 2024-08-06
Firefox CRITICAL 9.6
CVE-2024-7519

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a s…

Fix: 115.14.0 / 129.0+
Fix from $2,300 2024-08-06
Firefox HIGH 8.8
CVE-2024-7520

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129…

Fix: 128.1.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2024-7521

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox …

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2024-7522

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR <…

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2024-7527

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, …

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2024-7528

Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128…

Fix: 128.1.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox HIGH 8.8
CVE-2024-7530

Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.

Fix: 129.0+
Fix from $1,950 2024-08-06
Firefox Mobile HIGH 8.1
CVE-2024-7523

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This is…

Fix: 129+
Fix from $1,950 2024-08-06
Firefox HIGH 8.1
CVE-2024-7525

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of r…

Fix: 115.14.0 / 129.0+
Fix from $1,950 2024-08-06
Firefox MEDIUM 6.5
CVE-2024-7526

ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. Th…

Fix: 115.14.0 / 129.0+
Fix from $1,600 2024-08-06
Firefox MEDIUM 6.5
CVE-2024-7529

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vuln…

Fix: 115.14.0 / 129.0+
Fix from $1,600 2024-08-06
Firefox MEDIUM 6.5
CVE-2024-7531

Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processo…

Fix: 115.14.0 / 129.0+
Fix from $1,600 2024-08-06
Firefox MEDIUM 6.1
CVE-2024-7524

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Secur…

Fix: 115.14 / 128.1+
Fix from $1,600 2024-08-06
Firefox MEDIUM 6.5
CVE-2024-7518

Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerabil…

Fix: 128.1 / 129+
Fix from $1,600 2024-08-06
Firefox CRITICAL 9.8
CVE-2024-6611

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderb…

Fix: 128.0+
Fix from $2,300 2024-07-09
Firefox HIGH 8.8
CVE-2024-6615

Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Fix: 128.0+
Fix from $1,950 2024-07-09
Firefox MEDIUM 5.5
CVE-2024-6613

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Fire…

Fix: 128.0+
Fix from $1,600 2024-07-09
Firefox MEDIUM 5.3
CVE-2024-6612

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked…

Fix: 128.0+
Fix from $1,600 2024-07-09
Firefox CRITICAL 9.8
CVE-2024-6602

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thu…

Fix: 115.13 / 128.0+
Fix from $2,300 2024-07-09
Firefox HIGH 8.8
CVE-2024-6605

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

Fix: 128.0+
Fix from $1,950 2024-07-09