Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2022-46884

A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. This could have lead to m…

Fix: 106.0+
Fix from $1,950 2023-08-24
Firefox CRITICAL 9.8
CVE-2023-4056

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showe…

Fix: 102.14 / 115.1+
Fix from $2,300 2023-08-01
Firefox CRITICAL 9.8
CVE-2023-4057

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.1 / 116.0+
Fix from $2,300 2023-08-01
Firefox CRITICAL 9.8
CVE-2023-4058

Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 116.0+
Fix from $2,300 2023-08-01
Firefox HIGH 7.5
CVE-2023-4055

When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expecte…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Firefox MEDIUM 5.5
CVE-2023-4054

When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. …

Fix: 102.14 / 115.1+
Fix from $1,600 2023-08-01
Firefox HIGH 7.5
CVE-2023-4050EPSS 12%

In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash whi…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Firefox HIGH 7.5
CVE-2023-4051

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing…

Fix: 116.0+
Fix from $1,950 2023-08-01
Firefox MEDIUM 6.5
CVE-2023-4052

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively…

Fix: 115.1 / 116.0+
Fix from $1,600 2023-08-01
Firefox MEDIUM 6.5
CVE-2023-4053

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This co…

Fix: 116.0+
Fix from $1,600 2023-08-01
Firefox MEDIUM 5.9
CVE-2023-4049

Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vu…

Fix: 102.14 / 115.1+
Fix from $1,600 2023-08-01
Firefox HIGH 8.8
CVE-2023-4047

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerabil…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Firefox HIGH 7.5
CVE-2023-4048

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Fi…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Firefox MEDIUM 5.3
CVE-2023-4045

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same…

Fix: 102.14 / 115.1+
Fix from $1,600 2023-08-01
Firefox MEDIUM 5.3
CVE-2023-4046

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a po…

Fix: 102.14 / 115.1+
Fix from $1,600 2023-08-01
Firefox HIGH 8.8
CVE-2023-3600

During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerabil…

Fix: 115.0.1 / 115.0.2+
Fix from $1,950 2023-07-12
Firefox MEDIUM 6.5
CVE-2023-37456

The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

Fix: 115+
Fix from $1,600 2023-07-12
Firefox MEDIUM 5.4
CVE-2023-37455

The permission request prompt from the site in the background tab was overlaid on top of the site in the foreground tab. This vulnerability affects F…

Fix: 115+
Fix from $1,600 2023-07-12
Firefox HIGH 8.8
CVE-2023-37211

Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we…

Fix: 102.13 / 115.0+
Fix from $1,950 2023-07-05
Firefox HIGH 8.8
CVE-2023-37212

Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 115.0+
Fix from $1,950 2023-07-05
Firefox MEDIUM 6.5
CVE-2023-3482

When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of '…

Fix: 115.0+
Fix from $1,600 2023-07-05
Firefox HIGH 8.8
CVE-2023-37209

A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and a reference to that object re…

Fix: 115.0+
Fix from $1,950 2023-07-05
Firefox HIGH 7.8
CVE-2023-37203

Insufficient validation in the Drag and Drop API in conjunction with social engineering, may have allowed an attacker to trick end-users into creatin…

Fix: 115.0+
Fix from $1,950 2023-07-05
Firefox MEDIUM 6.5
CVE-2023-37204

A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This…

Fix: 115.0+
Fix from $1,600 2023-07-05
Firefox MEDIUM 6.5
CVE-2023-37205

The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115.

Fix: 115.0+
Fix from $1,600 2023-07-05
Firefox MEDIUM 6.5
CVE-2023-37206

Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulne…

Fix: 115.0+
Fix from $1,600 2023-07-05
Firefox MEDIUM 6.5
CVE-2023-37210

A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing att…

Fix: 115.0+
Fix from $1,600 2023-07-05
Firefox HIGH 7.8
CVE-2023-37208

When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Fire…

Fix: 102.13 / 115.0+
Fix from $1,950 2023-07-05
Firefox HIGH 8.8
CVE-2023-37201

An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, F…

Fix: 102.13 / 115.0+
Fix from $1,950 2023-07-05
Firefox HIGH 8.8
CVE-2023-37202

Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting…

Fix: 102.13 / 115.0+
Fix from $1,950 2023-07-05