Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2023-5731

Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 119.0+
Fix from $2,300 2023-10-25
Firefox HIGH 7.5
CVE-2023-5724

Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Fir…

Fix: 115.4 / 115.4.1+
Fix from $1,950 2023-10-25
Firefox HIGH 7.5
CVE-2023-5728

During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. Thi…

Fix: 115.4 / 115.4.1+
Fix from $1,950 2023-10-25
Firefox MEDIUM 6.5
CVE-2023-5727

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's c…

Fix: 115.4 / 115.4.1+
Fix from $1,600 2023-10-25
Firefox MEDIUM 6.5
CVE-2023-5732

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerabil…

Fix: 115.4.1 / 117.0+
Fix from $1,600 2023-10-25
Firefox MEDIUM 5.3
CVE-2023-5722

Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a server-supplied Vary header. This…

Fix: 119.0+
Fix from $1,600 2023-10-25
Firefox MEDIUM 5.3
CVE-2023-5723

An attacker with temporary script access to a site could have set a cookie containing invalid characters using `document.cookie` that could have led …

Fix: 119.0+
Fix from $1,600 2023-10-25
Common Voice MEDIUM 6.1
CVE-2023-42808

Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for traini…

No fix yet
Fix from $1,600 2023-10-04
Firefox HIGH 8.8
CVE-2023-5217 KEVEPSS 49%

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially ex…

Fix: 1.13.1 / 115.3.1+
Fix from $1,950 2023-09-28
Firefox CRITICAL 9.8
CVE-2023-5168

A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially ex…

Fix: 115.3 / 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5172

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitab…

Fix: 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5174

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-af…

Fix: 115.3 / 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5175

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, lead…

Fix: 118+
Fix from $2,300 2023-09-27
Firefox CRITICAL 9.8
CVE-2023-5176

Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.3 / 118+
Fix from $2,300 2023-09-27
Firefox HIGH 7.5
CVE-2023-5173

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unp…

Fix: 118+
Fix from $1,950 2023-09-27
Firefox HIGH 7.4
CVE-2023-5170

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged proce…

Fix: 118.0+
Fix from $1,950 2023-09-27
Firefox MEDIUM 6.5
CVE-2023-5169

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially e…

Fix: 115.3 / 118+
Fix from $1,600 2023-09-27
Firefox MEDIUM 6.5
CVE-2023-5171

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and caus…

Fix: 115.3 / 118+
Fix from $1,600 2023-09-27
Firefox HIGH 8.8
CVE-2023-4582

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private sha…

Fix: 115.2 / 117.0+
Fix from $1,950 2023-09-11
Firefox HIGH 8.8
CVE-2023-4584

Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showe…

Fix: 102.15 / 115.2+
Fix from $1,950 2023-09-11
Firefox HIGH 8.8
CVE-2023-4585

Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.2 / 117.0+
Fix from $1,950 2023-09-11
Firefox HIGH 8.6
CVE-2023-4576

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive…

Fix: 102.15 / 115.2+
Fix from $1,950 2023-09-11
Firefox HIGH 7.5
CVE-2023-4583

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have alread…

Fix: 115.2 / 117.0+
Fix from $1,950 2023-09-11
Firefox MEDIUM 6.5
CVE-2023-4574

When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventuall…

Fix: 102.15 / 115.2+
Fix from $1,600 2023-09-11
Firefox MEDIUM 6.5
CVE-2023-4575

When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually…

Fix: 102.15 / 115.2+
Fix from $1,600 2023-09-11
Firefox MEDIUM 6.5
CVE-2023-4577

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which…

Fix: 115.2 / 117.0+
Fix from $1,600 2023-09-11
Firefox MEDIUM 6.5
CVE-2023-4578

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the fun…

Fix: 115.2 / 117.0+
Fix from $1,600 2023-09-11
Firefox MEDIUM 6.5
CVE-2023-4580

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vuln…

Fix: 115.2 / 117.0+
Fix from $1,600 2023-09-11
Vpn MEDIUM 5.5
CVE-2023-4104

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN se…

Fix: 2.16.1+
Fix from $1,600 2023-09-11
Firefox MEDIUM 6.5
CVE-2023-4573

When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a poten…

Fix: 102.15 / 115.2+
Fix from $1,600 2023-09-11