Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2024-6607

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `<select>` e…

Fix: 128.0+
Fix from $1,950 2024-07-09
Firefox HIGH 8.8
CVE-2024-6609

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and T…

Fix: 128.0+
Fix from $1,950 2024-07-09
Firefox HIGH 8.2
CVE-2024-6606

Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 a…

Fix: 128.0+
Fix from $1,950 2024-07-09
Firefox HIGH 7.5
CVE-2024-6604

Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we…

Fix: 115.13 / 126.0+
Fix from $1,950 2024-07-09
Firefox HIGH 7.4
CVE-2024-6603

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vu…

Fix: 115.13 / 128.0+
Fix from $1,950 2024-07-09
Firefox MEDIUM 6.3
CVE-2024-6600

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in…

Fix: 115.13 / 128.0+
Fix from $1,600 2024-07-09
Firefox Mobile MEDIUM 6.5
CVE-2024-38312

When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundl…

Fix: 127.0+
Fix from $1,600 2024-06-13
Firefox CRITICAL 9.8
CVE-2024-5695

If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered,…

Fix: 127.0+
Fix from $2,300 2024-06-11
Firefox CRITICAL 9.8
CVE-2024-5699

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked w…

Fix: 127.0+
Fix from $2,300 2024-06-11
Firefox CRITICAL 9.8
CVE-2024-5701

Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 127.0+
Fix from $2,300 2024-06-11
Firefox HIGH 8.6
CVE-2024-5696

By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vul…

Fix: 115.12 / 127.0+
Fix from $1,950 2024-06-11
Firefox HIGH 7.5
CVE-2024-5702

Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < …

Fix: 115.12 / 125.0+
Fix from $1,950 2024-06-11
Firefox HIGH 7.0
CVE-2024-5700

Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we…

Fix: 115.12 / 127.0+
Fix from $1,950 2024-06-11
Firefox MEDIUM 6.1
CVE-2024-5698

By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have le…

Fix: 127+
Fix from $1,600 2024-06-11
Firefox HIGH 8.1
CVE-2024-5688

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Fi…

Fix: 115.12 / 127.0+
Fix from $1,950 2024-06-11
Firefox HIGH 7.5
CVE-2024-5694

An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerabili…

Fix: 127.0+
Fix from $1,950 2024-06-11
Firefox MEDIUM 6.5
CVE-2024-5692

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension su…

Fix: 115.12 / 127.0+
Fix from $1,600 2024-06-11
Firefox MEDIUM 6.1
CVE-2024-5693

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin…

Fix: 115.12 / 127.0+
Fix from $1,600 2024-06-11
Firefox MEDIUM 5.3
CVE-2024-5687

If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. …

Fix: 127.0+
Fix from $1,600 2024-06-11
Firefox CRITICAL 9.8
CVE-2024-4778

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 126.0+
Fix from $2,300 2024-05-14
Firefox HIGH 8.8
CVE-2024-4777

Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we…

Fix: 115.11.0 / 126.0+
Fix from $1,950 2024-05-14
Firefox HIGH 8.2
CVE-2024-4776

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

Fix: 126.0+
Fix from $1,950 2024-05-14
Firefox HIGH 7.5
CVE-2024-4773

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu…

Fix: 126.0+
Fix from $1,950 2024-05-14
Firefox MEDIUM 6.5
CVE-2024-4774

The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. Thi…

Fix: 126.0+
Fix from $1,600 2024-05-14
Firefox MEDIUM 5.9
CVE-2024-4772

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 1…

Fix: 126.0+
Fix from $1,600 2024-05-14
Firefox MEDIUM 5.9
CVE-2024-4775

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined b…

Fix: 126.0+
Fix from $1,600 2024-05-14
Firefox HIGH 8.8
CVE-2024-4770

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox …

Fix: 115.11.0 / 126.0+
Fix from $1,950 2024-05-14
Firefox HIGH 8.6
CVE-2024-4771

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially…

Fix: 126.0+
Fix from $1,950 2024-05-14
Firefox MEDIUM 6.1
CVE-2024-4768

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability …

Fix: 115.11.0 / 126.0+
Fix from $1,600 2024-05-14
Firefox MEDIUM 5.9
CVE-2024-4769

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script…

Fix: 115.11.0 / 126.0+
Fix from $1,600 2024-05-14