Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2020-15663

If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system…

Fix: 68.12 / 78.2+
Fix from $1,950 2020-10-01
Firefox HIGH 8.8
CVE-2020-15656

JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions…

Fix: 78.1 / 79.0+
Fix from $1,950 2020-08-10
Firefox HIGH 8.8
CVE-2020-15659

Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence o…

Fix: 68.11 / 78.1.0+
Fix from $1,950 2020-08-10
Firefox HIGH 7.8
CVE-2020-15657

Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placi…

Fix: 78.1 / 79.0+
Fix from $1,950 2020-08-10
Firefox MEDIUM 6.5
CVE-2020-15648

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerabi…

Fix: 78.0 / 78.0.2+
Fix from $1,600 2020-08-10
Firefox MEDIUM 6.5
CVE-2020-15652

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only t…

Fix: 68.11 / 78.1+
Fix from $1,600 2020-08-10
Firefox MEDIUM 6.5
CVE-2020-15653

An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites…

Fix: 78.1 / 79.0+
Fix from $1,600 2020-08-10
Firefox MEDIUM 6.5
CVE-2020-15654

When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when…

Fix: 78.1 / 79.0+
Fix from $1,600 2020-08-10
Firefox MEDIUM 6.5
CVE-2020-15655

A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of…

Fix: 78.1 / 79.0+
Fix from $1,600 2020-08-10
Firefox MEDIUM 6.5
CVE-2020-15658

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an…

Fix: 78.1 / 79.0+
Fix from $1,600 2020-08-10
Firefox Mobile MEDIUM 6.5
CVE-2020-15661

A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current…

Fix: 28.0+
Fix from $1,600 2020-08-10
Firefox Mobile MEDIUM 6.5
CVE-2020-15662

A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintende…

Fix: 28.0+
Fix from $1,600 2020-08-10
Firefox Esr MEDIUM 5.5
CVE-2020-15649

Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actua…

Fix: 68.11+
Fix from $1,600 2020-08-10
Firefox Esr MEDIUM 5.5
CVE-2020-15650

Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not acce…

Fix: 68.11+
Fix from $1,600 2020-08-10
Firefox HIGH 7.4
CVE-2020-15647

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data dis…

Fix: 68.10.1+
Fix from $1,950 2020-08-10
Firefox HIGH 8.8
CVE-2020-12422

In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds …

Fix: 78.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12426

Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption a…

Fix: 78.0+
Fix from $1,950 2020-07-09
Firefox HIGH 7.8
CVE-2020-12423

When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox m…

Fix: 78.0+
Fix from $1,950 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12421

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an admini…

Fix: 68.10.0 / 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12425

Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information d…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox HIGH 8.8
CVE-2020-12406

Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effo…

Fix: 68.9.0 / 77.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12409

When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox…

Fix: 77.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12410

Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption an…

Fix: 68.8.0 / 76.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12411

Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 77.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12416

A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption…

Fix: 78.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12417

Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially…

Fix: 68.10.0 / 78.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12419

When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free conditi…

Fix: 68.10 / 68.10.0+
Fix from $1,950 2020-07-09
Firefox HIGH 8.8
CVE-2020-12420

When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potenti…

Fix: 68.10.0 / 78.0+
Fix from $1,950 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12407

Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible scre…

Fix: 77.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12408

When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar.…

Fix: 77.0+
Fix from $1,600 2020-07-09