Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.5
CVE-2007-5967

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

Mitigation only
Fix from $1,600 2021-05-17
Firefox HIGH 8.8
CVE-2021-23987

Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence o…

Fix: 78.9 / 87.0+
Fix from $1,950 2021-03-31
Firefox HIGH 8.8
CVE-2021-23988

Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 87.0+
Fix from $1,950 2021-03-31
Firefox MEDIUM 6.5
CVE-2021-23982

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services r…

Fix: 78.9 / 87.0+
Fix from $1,600 2021-03-31
Firefox MEDIUM 6.5
CVE-2021-23983

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corrup…

Fix: 87.0+
Fix from $1,600 2021-03-31
Firefox MEDIUM 6.5
CVE-2021-23984

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully cont…

Fix: 78.9 / 87.0+
Fix from $1,600 2021-03-31
Firefox MEDIUM 6.5
CVE-2021-23985

If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feat…

Fix: 87.0+
Fix from $1,600 2021-03-31
Firefox MEDIUM 6.5
CVE-2021-23986

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response…

Fix: 87.0+
Fix from $1,600 2021-03-31
Firefox HIGH 8.1
CVE-2021-23981

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corrup…

Fix: 78.9 / 87.0+
Fix from $1,950 2021-03-31
Pollbot MEDIUM 6.1
CVE-2021-21354

Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p…

Fix: 1.4.4+
Fix from $1,600 2021-03-08
Firefox HIGH 8.8
CVE-2021-23964

Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption an…

Fix: 78.7 / 85.0+
Fix from $1,950 2021-02-26
Firefox HIGH 8.8
CVE-2021-23965

Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 85.0+
Fix from $1,950 2021-02-26
Firefox HIGH 8.8
CVE-2021-23978

Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption an…

Fix: 78.8 / 86.0+
Fix from $1,950 2021-02-26
Firefox HIGH 8.8
CVE-2021-23979

Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 86.0+
Fix from $1,950 2021-02-26
Firefox HIGH 8.8
CVE-2021-23962

Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects…

Fix: 85.0+
Fix from $1,950 2021-02-26
Firefox MEDIUM 5.3
CVE-2021-23977

Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from applicat…

Fix: 86.0+
Fix from $1,600 2021-02-26
Firefox HIGH 8.8
CVE-2021-23954

Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a …

Fix: 78.7 / 85.0+
Fix from $1,950 2021-02-26
Firefox HIGH 8.8
CVE-2021-23960

Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerab…

Fix: 78.7 / 85.0+
Fix from $1,950 2021-02-26
Firefox HIGH 7.4
CVE-2021-23957

Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox…

Fix: 85.0+
Fix from $1,950 2021-02-26
Firefox HIGH 7.4
CVE-2021-23961

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as wel…

Fix: 85.0+
Fix from $1,950 2021-02-26
Firefox MEDIUM 6.5
CVE-2021-23956

An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was …

Fix: 85.0+
Fix from $1,600 2021-02-26
Firefox MEDIUM 6.5
CVE-2021-23958

The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnera…

Fix: 85.0+
Fix from $1,600 2021-02-26
Firefox MEDIUM 6.1
CVE-2021-23955

The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vul…

Fix: 85.0+
Fix from $1,600 2021-02-26
Firefox MEDIUM 6.1
CVE-2021-23959

An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only…

Fix: 85.0+
Fix from $1,600 2021-02-26
Firefox HIGH 8.8
CVE-2021-23972

One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]'. To mitigate this type of a…

Fix: 86.0+
Fix from $1,950 2021-02-26
Firefox HIGH 8.1
CVE-2021-23976

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring w…

Fix: 86.0+
Fix from $1,950 2021-02-26
Firefox MEDIUM 6.5
CVE-2021-23970

Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability aff…

Fix: 86.0+
Fix from $1,600 2021-02-26
Firefox MEDIUM 6.5
CVE-2021-23971

When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially…

Fix: 86.0+
Fix from $1,600 2021-02-26
Firefox MEDIUM 6.5
CVE-2021-23973

When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have reve…

Fix: 78.8 / 86.0+
Fix from $1,600 2021-02-26
Firefox MEDIUM 6.5
CVE-2021-23975

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function …

Fix: 86.0+
Fix from $1,600 2021-02-26