Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox Mobile MEDIUM 6.5
CVE-2020-12414

IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requi…

Fix: 27.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12415

When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirector…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12418

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerabi…

Fix: 68.10 / 68.10.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 5.3
CVE-2020-12405

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerabili…

Fix: 68.9.0 / 77.0+
Fix from $1,600 2020-07-09
Firefox HIGH 8.8
CVE-2018-12371

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This resul…

Fix: 60.0 / 60.1.0+
Fix from $1,950 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12424

When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox CRITICAL 10.0
CVE-2020-12388

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 10.0
CVE-2020-12389

The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Fir…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-12390

Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

Fix: 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-6831EPSS 6%

A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitab…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox HIGH 7.5
CVE-2020-12391

Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that …

Fix: 76.0+
Fix from $1,950 2020-05-26
Firefox Mobile HIGH 7.5
CVE-2020-6830

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was b…

Fix: 25.0+
Fix from $1,950 2020-05-26
Firefox MEDIUM 5.5
CVE-2020-12392

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. …

Fix: 68.8.0 / 76.0+
Fix from $1,600 2020-05-26
Firefox HIGH 8.1
CVE-2020-12387

A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. T…

Fix: 68.8.0 / 76.0+
Fix from $1,950 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-12395

Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence o…

Fix: 68.8.0 / 76.0+
Fix from $2,300 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-12396

Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption a…

Fix: 76.0+
Fix from $2,300 2020-05-26
Firefox HIGH 7.8
CVE-2020-12393

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If …

Fix: 68.8.0 / 76.0+
Fix from $1,950 2020-05-26
Firefox CRITICAL 9.8
CVE-2020-6823

A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise return…

Fix: 75.0+
Fix from $2,300 2020-04-24
Firefox CRITICAL 9.8
CVE-2020-6825

Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Som…

Fix: 68.7.0 / 75.0+
Fix from $2,300 2020-04-24
Firefox CRITICAL 9.8
CVE-2020-6826

Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showed evidence…

Fix: 75.0+
Fix from $2,300 2020-04-24
Firefox HIGH 8.8
CVE-2020-6822

On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is possible …

Fix: 68.7.0 / 75.0+
Fix from $1,950 2020-04-24
Firefox HIGH 8.1
CVE-2020-6819 KEV

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Firefox HIGH 8.1
CVE-2020-6820 KEVEPSS 6%

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild a…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Firefox HIGH 7.5
CVE-2020-6821

When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires t…

Fix: 68.7.0 / 75.0+
Fix from $1,950 2020-04-24
Firefox Esr HIGH 7.5
CVE-2020-6828

A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrit…

Fix: 68.7.0+
Fix from $1,950 2020-04-24
Firefox CRITICAL 9.8
CVE-2020-6814

Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and w…

Fix: 68.6.0 / 74.0+
Fix from $2,300 2020-03-25
Firefox CRITICAL 9.8
CVE-2020-6815

Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or es…

Fix: 74.0+
Fix from $2,300 2020-03-25
Firefox HIGH 8.8
CVE-2020-6805

When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially explo…

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Firefox HIGH 8.8
CVE-2020-6806

By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. Th…

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Firefox HIGH 8.8
CVE-2020-6807

When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was d…

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25