Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.5
CVE-2020-26965

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.5
CVE-2020-26966

Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that s…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.5
CVE-2020-26967

When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other…

Fix: 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.1
CVE-2020-26958

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.1
CVE-2020-26962

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used i…

Fix: 83.0+
Fix from $1,600 2020-12-09
Firefox HIGH 8.8
CVE-2020-26950EPSS 42%

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. Thi…

Fix: 78.4.1 / 78.4.2+
Fix from $1,950 2020-12-09
Firefox HIGH 8.8
CVE-2020-26952

Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handli…

Fix: 83.0+
Fix from $1,950 2020-12-09
Firefox Mobile MEDIUM 6.5
CVE-2020-26955

When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on t…

Fix: 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.1
CVE-2020-26951

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capab…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 6.1
CVE-2020-26956

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affect…

Fix: 78.5 / 83.0+
Fix from $1,600 2020-12-09
Firefox MEDIUM 5.3
CVE-2020-6829

When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce us…

Fix: 80.0+
Fix from $1,600 2020-10-28
Firefox CRITICAL 9.8
CVE-2020-15683

Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence o…

Fix: 78.4 / 82.0+
Fix from $2,300 2020-10-22
Firefox CRITICAL 9.8
CVE-2020-15684

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 82.0+
Fix from $2,300 2020-10-22
Firefox HIGH 7.5
CVE-2020-15681

When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entr…

Fix: 82.0+
Fix from $1,950 2020-10-22
Firefox MEDIUM 6.5
CVE-2020-15682

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker c…

Fix: 82.0+
Fix from $1,600 2020-10-22
Firefox MEDIUM 5.3
CVE-2020-15680

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size …

Fix: 82.0+
Fix from $1,600 2020-10-22
Network Security Services HIGH 7.5
CVE-2019-17007

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

Fix: 2.14.0 / 3.44+
Fix from $1,950 2020-10-22
Network Security Services MEDIUM 6.5
CVE-2018-18508

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a…

Fix: 2.14.0 / 3.36.7+
Fix from $1,600 2020-10-22
Thunderbird MEDIUM 5.9
CVE-2020-15646

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and …

Fix: 68.10.0+
Fix from $1,600 2020-10-08
Firefox HIGH 8.8
CVE-2020-15667

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory …

Fix: 80.0+
Fix from $1,950 2020-10-01
Firefox Esr HIGH 8.8
CVE-2020-15669

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-fr…

Fix: 68.12+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15670

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we pres…

Fix: 78.2 / 80.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15673

Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption an…

Fix: 78.3 / 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15674

Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15675

When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnera…

Fix: 81.0+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15678

When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs be…

Fix: 78.3 / 81.0+
Fix from $1,950 2020-10-01
Firefox MEDIUM 6.5
CVE-2020-15664

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object w…

Fix: 68.12 / 78.2+
Fix from $1,600 2020-10-01
Firefox MEDIUM 6.5
CVE-2020-15666

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError…

Fix: 80.0+
Fix from $1,600 2020-10-01
Firefox MEDIUM 6.1
CVE-2020-15676

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after past…

Fix: 78.3 / 81.0+
Fix from $1,600 2020-10-01
Firefox MEDIUM 6.1
CVE-2020-15677

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the …

Fix: 78.3 / 81.0+
Fix from $1,600 2020-10-01