Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.5
CVE-2023-37207

A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This cou…

Fix: 102.13 / 115.0+
Fix from $1,600 2023-07-05
Firefox CRITICAL 9.8
CVE-2023-34416

Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we…

Fix: 102.12 / 114.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-34417

Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 114.0+
Fix from $2,300 2023-06-19
Firefox MEDIUM 6.1
CVE-2023-34415

When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in t…

Fix: 114.0+
Fix from $1,600 2023-06-19
Firefox CRITICAL 10.0
CVE-2019-25136

A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. T…

Fix: 70.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-25736

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.

Fix: 110.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-29542

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk wi…

Fix: 102.10 / 112.0+
Fix from $2,300 2023-06-19
Firefox Focus CRITICAL 9.1
CVE-2023-29534

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusi…

Fix: 112.0+
Fix from $2,300 2023-06-19
Firefox HIGH 7.5
CVE-2023-25733

The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference. This vul…

Fix: 110.0+
Fix from $1,950 2023-06-19
Firefox Mobile HIGH 7.5
CVE-2023-25747

A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects…

Fix: 110.1+
Fix from $1,950 2023-06-19
Firefox MEDIUM 6.5
CVE-2023-29545

Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved thos…

Fix: 102.10 / 112.0+
Fix from $1,600 2023-06-19
Firefox Focus MEDIUM 6.5
CVE-2023-29546

When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitiv…

Fix: 112.0+
Fix from $1,600 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-29531

An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *Th…

Fix: 102.10 / 112.0+
Fix from $2,300 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-32216

Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs prese…

Fix: 113.0+
Fix from $2,300 2023-06-19
Firefox HIGH 7.5
CVE-2023-32209

A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.

Fix: 113.0+
Fix from $1,950 2023-06-19
Firefox HIGH 7.5
CVE-2023-32214

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other…

Fix: 102.11 / 113.0+
Fix from $1,950 2023-06-19
Firefox MEDIUM 6.5
CVE-2023-32210

Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain …

Fix: 113.0+
Fix from $1,600 2023-06-19
Firefox MEDIUM 5.5
CVE-2023-29532

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malic…

Fix: 102.10 / 112.0+
Fix from $1,600 2023-06-19
Firefox MEDIUM 5.3
CVE-2023-32208

Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.

Fix: 113.0+
Fix from $1,600 2023-06-19
Firefox HIGH 8.8
CVE-2023-29551

Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 112.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2023-32207

A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affe…

Fix: 102.11 / 113.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2023-32213

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and T…

Fix: 102.11 / 113.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2023-32215

Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing …

Fix: 102.11 / 113.0+
Fix from $1,950 2023-06-02
Firefox MEDIUM 6.5
CVE-2023-32206

An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunder…

Fix: 102.11 / 113.0+
Fix from $1,600 2023-06-02
Firefox MEDIUM 6.5
CVE-2023-32211

A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < …

Fix: 102.11 / 113.0+
Fix from $1,600 2023-06-02
Firefox HIGH 8.8
CVE-2023-28161

If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission pers…

Fix: 111.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2023-28162

While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploita…

Fix: 102.9 / 111.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2023-28176

Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with eno…

Fix: 102.9 / 111.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2023-28177

Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 111.0+
Fix from $1,950 2023-06-02
Firefox HIGH 8.8
CVE-2023-29536

An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory…

Fix: 102.10 / 112.0+
Fix from $1,950 2023-06-02