Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thunderbird MEDIUM 5.9
CVE-2021-29969

If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the S…

Fix: 78.12+
Fix from $1,600 2021-08-05
Hubs Cloud MEDIUM 6.1
CVE-2021-29979

Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s prim…

Mitigation only
Fix from $1,600 2021-08-02
Geckodriver HIGH 8.8
CVE-2020-15660

Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically p…

Fix: 0.27.0+
Fix from $1,950 2021-07-20
Hubs Cloud Reticulum CRITICAL 9.8
CVE-2021-29954

Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability af…

Fix: 1.0.1+
Fix from $2,300 2021-06-24
Firefox HIGH 8.8
CVE-2021-29966

Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 89.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-29967

Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption a…

Fix: 78.11 / 89.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.1
CVE-2021-29968

When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operatin…

Fix: 89.0.1+
Fix from $1,950 2021-06-24
Firefox HIGH 7.1
CVE-2021-29964

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This…

Fix: 78.11 / 89.0+
Fix from $1,950 2021-06-24
Firefox MEDIUM 6.1
CVE-2021-29953

A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resu…

Fix: 88.0.1 / 88.1.3+
Fix from $1,600 2021-06-24
Firefox MEDIUM 5.3
CVE-2021-29955

A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have …

Fix: 78.9 / 87.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 5.3
CVE-2021-29965

A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the cu…

Fix: 89.0+
Fix from $1,600 2021-06-24
Firefox HIGH 8.8
CVE-2021-23994

A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ES…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-23995

When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-23997

Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effor…

Fix: 88.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-23999

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges t…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-24002

When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed a…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-29946

Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the A…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-29947

Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption a…

Fix: 88.0+
Fix from $1,950 2021-06-24
Thunderbird HIGH 7.8
CVE-2021-29949

When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that is…

Fix: 78.9.1+
Fix from $1,950 2021-06-24
Thunderbird HIGH 7.5
CVE-2021-29950

Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secr…

Fix: 78.8.1+
Fix from $1,950 2021-06-24
Firefox HIGH 7.5
CVE-2021-29952

When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have be…

Fix: 88.0.1 / 88.1.3+
Fix from $1,950 2021-06-24
Thunderbird MEDIUM 6.8
CVE-2021-23991

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has…

Fix: 78.9.1+
Fix from $1,600 2021-06-24
Thunderbird MEDIUM 6.5
CVE-2021-23993

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key …

Fix: 78.9.1+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.5
CVE-2021-23996

By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofing attack t…

Fix: 88.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.5
CVE-2021-23998

Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects…

Fix: 78.10 / 88.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.5
CVE-2021-29945

The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affec…

Fix: 78.10 / 88.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.5
CVE-2021-29951

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start …

Fix: 78.10.1 / 87.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.1
CVE-2021-29944

Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTM…

Fix: 88.0+
Fix from $1,600 2021-06-24
Firefox MEDIUM 6.1
CVE-2011-3656

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or…

Fix: 3.6.24+
Fix from $1,600 2021-06-02
Nss CRITICAL 9.1
CVE-2020-12403

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-b…

Fix: 3.55+
Fix from $2,300 2021-05-27