Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.1
CVE-2024-4765

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. T…

Fix: 126.0+
Fix from $1,950 2024-05-14
Firefox CRITICAL 9.8
CVE-2024-4764

Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

Fix: 126.0+
Fix from $2,300 2024-05-14
Firefox HIGH 8.8
CVE-2024-4367EPSS 73%

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability af…

Fix: 7.10.6 / 115.11.0+
Fix from $1,950 2024-05-14
Firefox CRITICAL 9.8
CVE-2024-3863

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other oper…

Fix: 115.10 / 115.10.0+
Fix from $2,300 2024-04-16
Firefox HIGH 8.8
CVE-2024-3854

In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox…

Fix: 115.10 / 125.0+
Fix from $1,950 2024-04-16
Firefox HIGH 8.8
CVE-2024-3856

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 12…

Fix: 125.0+
Fix from $1,950 2024-04-16
Firefox HIGH 8.1
CVE-2024-3864

Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that…

Fix: 115.10.0 / 125.0+
Fix from $1,950 2024-04-16
Firefox HIGH 8.1
CVE-2024-3865

Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 125.0+
Fix from $1,950 2024-04-16
Firefox HIGH 7.8
CVE-2024-3857

The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerabi…

Fix: 115.10 / 125.0+
Fix from $1,950 2024-04-16
Firefox HIGH 7.5
CVE-2024-3852

GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR <…

Fix: 115.10 / 125.0+
Fix from $1,950 2024-04-16
Firefox HIGH 7.5
CVE-2024-3853

A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability aff…

Fix: 125.0+
Fix from $1,950 2024-04-16
Firefox HIGH 7.5
CVE-2024-3858

It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.

Fix: 125.0+
Fix from $1,950 2024-04-16
Firefox MEDIUM 6.5
CVE-2024-3855

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

Fix: 125.0+
Fix from $1,600 2024-04-16
Firefox MEDIUM 6.2
CVE-2024-3860

An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash…

Fix: 125.0+
Fix from $1,600 2024-04-16
Firefox MEDIUM 5.9
CVE-2024-3859

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. T…

Fix: 115.10 / 125.0+
Fix from $1,600 2024-04-16
Firefox MEDIUM 5.3
CVE-2024-3862

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulner…

Fix: 125.0+
Fix from $1,600 2024-04-16
Firefox HIGH 7.5
CVE-2024-31392

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnera…

Fix: 124.0+
Fix from $1,950 2024-04-03
Firefox CRITICAL 9.8
CVE-2024-29943EPSS 23%

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerabi…

Fix: 124.0.1+
Fix from $2,300 2024-03-22
Firefox HIGH 8.4
CVE-2024-29944

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note:…

Fix: 115.9.1+
Fix from $1,950 2024-03-22
Firefox CRITICAL 9.8
CVE-2024-2615

Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 124.0+
Fix from $2,300 2024-03-19
Firefox HIGH 8.8
CVE-2024-2614

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.8.0 / 123.0+
Fix from $1,950 2024-03-19
Firefox HIGH 8.1
CVE-2024-2612

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to ach…

Fix: 115.9 / 124.0+
Fix from $1,950 2024-03-19
Firefox HIGH 7.5
CVE-2024-2613

Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerabilit…

Fix: 124.0+
Fix from $1,950 2024-03-19
Firefox MEDIUM 5.5
CVE-2024-2611

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affec…

Fix: 115.9.0 / 124.0+
Fix from $1,600 2024-03-19
Firefox HIGH 8.4
CVE-2024-2608

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing …

Fix: 115.9.0 / 124.0+
Fix from $1,950 2024-03-19
Firefox HIGH 8.1
CVE-2024-2607

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. O…

Fix: 115.9.0 / 124.0+
Fix from $1,950 2024-03-19
Firefox MEDIUM 6.1
CVE-2024-2609

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This…

Fix: 115.10.0 / 124.0+
Fix from $1,600 2024-03-19
Firefox MEDIUM 6.1
CVE-2024-2610

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulne…

Fix: 115.9.0 / 124.0+
Fix from $1,600 2024-03-19
Firefox MEDIUM 5.9
CVE-2024-2605

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affecte…

Fix: 115.9.0 / 124.0+
Fix from $1,600 2024-03-19
Firefox MEDIUM 6.5
CVE-2023-5388

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the pr…

Fix: 115.9.0 / 124.0+
Fix from $1,600 2024-03-19