Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2023-6873

Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 121.0+
Fix from $1,950 2023-12-19
Firefox MEDIUM 6.5
CVE-2023-6869

A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display und…

Fix: 121.0+
Fix from $1,600 2023-12-19
Firefox MEDIUM 6.5
CVE-2023-6872

Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the browsing habits of users running in a private tab. Th…

Fix: 121.0+
Fix from $1,600 2023-12-19
Firefox HIGH 8.8
CVE-2023-6856EPSS 20%

The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could al…

Fix: 115.6 / 121.0+
Fix from $1,950 2023-12-19
Firefox HIGH 8.8
CVE-2023-6858

Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.…

Fix: 115.6 / 121.0+
Fix from $1,950 2023-12-19
Firefox HIGH 8.8
CVE-2023-6859

A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115…

Fix: 115.6 / 121.0+
Fix from $1,950 2023-12-19
Firefox HIGH 8.8
CVE-2023-6861

The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox E…

Fix: 115.6 / 121.0+
Fix from $1,950 2023-12-19
Firefox Esr HIGH 8.8
CVE-2023-6862

A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firef…

Fix: 115.6+
Fix from $1,950 2023-12-19
Firefox HIGH 8.8
CVE-2023-6863

The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. Th…

Fix: 115.6 / 121.0+
Fix from $1,950 2023-12-19
Firefox HIGH 8.8
CVE-2023-6864

Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.6 / 121.0+
Fix from $1,950 2023-12-19
Firefox HIGH 8.8
CVE-2023-6866

TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. …

Fix: 121.0+
Fix from $1,950 2023-12-19
Firefox MEDIUM 6.5
CVE-2023-6860

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerab…

Fix: 115.6 / 121.0+
Fix from $1,600 2023-12-19
Firefox MEDIUM 6.5
CVE-2023-6865

`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk whic…

Fix: 115.6 / 121.0+
Fix from $1,600 2023-12-19
Firefox MEDIUM 6.1
CVE-2023-6867

The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It …

Fix: 115.6 / 121.0+
Fix from $1,600 2023-12-19
Firefox MEDIUM 5.3
CVE-2023-6857

When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Fire…

Fix: 115.6 / 121.0+
Fix from $1,600 2023-12-19
Nss MEDIUM 6.5
CVE-2023-4421

The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of th…

Fix: 3.6.1+
Fix from $1,600 2023-12-12
Firefox HIGH 8.8
CVE-2023-6212

Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.5 / 115.5.0+
Fix from $1,950 2023-11-21
Firefox HIGH 8.8
CVE-2023-6213

Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 120.0+
Fix from $1,950 2023-11-21
Firefox MEDIUM 6.5
CVE-2023-6210

When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from…

Fix: 120.0+
Fix from $1,600 2023-11-21
Firefox MEDIUM 6.5
CVE-2023-6211

If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user …

Fix: 120.0+
Fix from $1,600 2023-11-21
Firefox Mobile CRITICAL 9.8
CVE-2023-49060

An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulne…

Fix: 120.0+
Fix from $2,300 2023-11-21
Firefox HIGH 8.8
CVE-2023-6207

Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbi…

Fix: 115.5 / 115.5.0+
Fix from $1,950 2023-11-21
Firefox HIGH 8.8
CVE-2023-6208

When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike t…

Fix: 115.5 / 115.5.0+
Fix from $1,950 2023-11-21
Firefox MEDIUM 6.5
CVE-2023-6204

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images cr…

Fix: 115.5 / 115.5.0+
Fix from $1,600 2023-11-21
Firefox MEDIUM 6.5
CVE-2023-6205

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vul…

Fix: 115.5 / 115.5.0+
Fix from $1,600 2023-11-21
Firefox MEDIUM 6.5
CVE-2023-6209

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specifi…

Fix: 115.5 / 115.5.0+
Fix from $1,600 2023-11-21
Firefox Mobile MEDIUM 6.1
CVE-2023-49061

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS…

Fix: 120.0+
Fix from $1,600 2023-11-21
Firefox MEDIUM 5.4
CVE-2023-6206

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use t…

Fix: 115.5 / 115.5.0+
Fix from $1,600 2023-11-21
Firefox Mobile MEDIUM 6.1
CVE-2023-5758

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS…

Fix: 119.0+
Fix from $1,600 2023-10-25
Firefox CRITICAL 9.8
CVE-2023-5730

Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.4 / 115.4.1+
Fix from $2,300 2023-10-25