Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.1
CVE-2022-22753

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directo…

Fix: 91.6 / 97.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22754

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grant…

Fix: 91.6 / 97.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22747

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is …

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22748

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. T…

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22750

By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes t…

Fix: 96.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-22744

The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command inj…

Fix: 91.5 / 96.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22745

Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91…

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 5.9
CVE-2022-22746

A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*Thi…

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox HIGH 8.8
CVE-2022-22738

Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitab…

Fix: 91.5 / 96.0+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-22740

Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a pote…

Fix: 91.5 / 96.0+
Fix from $1,950 2022-12-22
Firefox HIGH 7.5
CVE-2022-22737

Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free c…

Fix: 91.5 / 96.0+
Fix from $1,950 2022-12-22
Firefox HIGH 7.5
CVE-2022-22741

When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Fir…

Fix: 91.5 / 96.0+
Fix from $1,950 2022-12-22
Firefox HIGH 7.0
CVE-2022-22736

If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for syst…

Fix: 96.0+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22739

Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox…

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-22742

When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This …

Fix: 91.5 / 96.0+
Fix from $1,600 2022-12-22
Firefox CRITICAL 9.8
CVE-2022-1887

The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.

Fix: 101+
Fix from $2,300 2022-12-22
Firefox HIGH 8.8
CVE-2022-1529EPSS 17%

An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototy…

Fix: 91.9.1 / 100.0.2+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-1802EPSS 27%

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attack…

Fix: 91.9.1 / 100.0.2+
Fix from $1,950 2022-12-22
Thunderbird MEDIUM 6.5
CVE-2022-1834

When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would hav…

Fix: 91.10+
Fix from $1,600 2022-12-22
Thunderbird MEDIUM 5.4
CVE-2022-1197

When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was…

Fix: 91.8+
Fix from $1,600 2022-12-22
Firefox CRITICAL 10.0
CVE-2021-4140

It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Fire…

Fix: 91.5 / 96.0+
Fix from $2,300 2022-12-22
Firefox CRITICAL 9.8
CVE-2021-4129

Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported m…

Fix: 91.4.0 / 95.0+
Fix from $2,300 2022-12-22
Firefox HIGH 8.8
CVE-2022-0511

Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team …

Fix: 97.0+
Fix from $1,950 2022-12-22
Thunderbird HIGH 8.8
CVE-2022-0566

It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing th…

Fix: 91.6.1+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-0843

Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed e…

Fix: 97.0+
Fix from $1,950 2022-12-22
Vpn HIGH 7.8
CVE-2022-0517

Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to lau…

Fix: 2.7.1+
Fix from $1,950 2022-12-22
Firefox MEDIUM 6.5
CVE-2022-1097

<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use…

Fix: 91.8 / 99.0+
Fix from $1,600 2022-12-22
Firefox Esr MEDIUM 6.5
CVE-2022-1196

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. Th…

Fix: 91.8+
Fix from $1,600 2022-12-22
Firefox Esr CRITICAL 9.8
CVE-2021-4127

An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird …

Fix: 78.9.0+
Fix from $2,300 2022-12-22
Thunderbird HIGH 8.8
CVE-2020-15685

During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. T…

Fix: 78.7.0+
Fix from $1,950 2022-12-22