Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox Focus HIGH 8.1
CVE-2024-1563

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox sc…

Fix: 122.0+
Fix from $1,950 2024-02-22
Firefox HIGH 7.8
CVE-2024-26283

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox sc…

Fix: 123.0+
Fix from $1,950 2024-02-22
Firefox HIGH 7.1
CVE-2024-26282

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Fire…

Fix: 123.0+
Fix from $1,950 2024-02-22
Firefox Focus MEDIUM 6.1
CVE-2024-26284

Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to t…

Fix: 123.0+
Fix from $1,600 2024-02-22
Firefox HIGH 8.3
CVE-2024-1555

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 12…

Fix: 123.0+
Fix from $1,950 2024-02-20
Firefox HIGH 8.1
CVE-2024-1557

Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 123.0+
Fix from $1,950 2024-02-20
Firefox MEDIUM 6.5
CVE-2024-1556

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This…

Fix: 123.0+
Fix from $1,600 2024-02-20
Firefox CRITICAL 9.8
CVE-2024-1554

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Und…

Fix: 123.0+
Fix from $2,300 2024-02-20
Firefox HIGH 8.1
CVE-2024-1553

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.8.0 / 123.0+
Fix from $1,950 2024-02-20
Firefox HIGH 7.5
CVE-2024-1546

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. …

Fix: 115.8.0 / 123.0+
Fix from $1,950 2024-02-20
Firefox HIGH 7.5
CVE-2024-1552

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit AR…

Fix: 115.8.0 / 123.0+
Fix from $1,950 2024-02-20
Firefox MEDIUM 6.5
CVE-2024-1547

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim websit…

Fix: 115.8.0 / 123.0+
Fix from $1,600 2024-02-20
Firefox MEDIUM 6.1
CVE-2024-1549

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confus…

Fix: 115.8.0 / 123.0+
Fix from $1,600 2024-02-20
Firefox MEDIUM 6.1
CVE-2024-1550

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned u…

Fix: 115.8.0 / 123.0+
Fix from $1,600 2024-02-20
Firefox MEDIUM 6.1
CVE-2024-1551

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header…

Fix: 115.8.0 / 123.0+
Fix from $1,600 2024-02-20
Firefox Mobile MEDIUM 6.1
CVE-2024-0953

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi…

No fix yet
Fix from $1,600 2024-02-05
Firefox HIGH 8.8
CVE-2024-0745

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnera…

Fix: 122.0+
Fix from $1,950 2024-01-23
Firefox HIGH 8.8
CVE-2024-0750

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerabil…

Fix: 115.7 / 122.0+
Fix from $1,950 2024-01-23
Firefox HIGH 8.8
CVE-2024-0751

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde…

Fix: 115.7 / 122.0+
Fix from $1,950 2024-01-23
Firefox HIGH 8.8
CVE-2024-0755

Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.7 / 122.0+
Fix from $1,950 2024-01-23
Firefox HIGH 7.5
CVE-2024-0743

An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox …

Fix: 122.0+
Fix from $1,950 2024-01-23
Firefox HIGH 7.5
CVE-2024-0744

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerabilit…

Fix: 122.0+
Fix from $1,950 2024-01-23
Firefox MEDIUM 6.5
CVE-2024-0741

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affec…

Fix: 115.7 / 122.0+
Fix from $1,600 2024-01-23
Firefox MEDIUM 6.5
CVE-2024-0746

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, …

Fix: 115.7 / 122.0+
Fix from $1,600 2024-01-23
Firefox MEDIUM 6.5
CVE-2024-0747

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Secur…

Fix: 115.7 / 122.0+
Fix from $1,600 2024-01-23
Firefox MEDIUM 6.5
CVE-2024-0752

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an expl…

Fix: 122.0+
Fix from $1,600 2024-01-23
Firefox MEDIUM 6.5
CVE-2024-0753

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, a…

Fix: 115.7 / 122.0+
Fix from $1,600 2024-01-23
Firefox MEDIUM 6.5
CVE-2024-0754

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

Fix: 122.0+
Fix from $1,600 2024-01-23
Firefox Focus HIGH 7.5
CVE-2024-0605

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses s…

Fix: 122.0+
Fix from $1,950 2024-01-22
Firefox Focus MEDIUM 6.1
CVE-2024-0606

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthoriz…

Fix: 122.0+
Fix from $1,600 2024-01-22