Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2020-6811

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If …

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Firefox HIGH 7.5
CVE-2020-6809

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to …

Fix: 74.0+
Fix from $1,950 2020-03-25
Firefox MEDIUM 6.5
CVE-2020-6808

When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presente…

Fix: 74.0+
Fix from $1,600 2020-03-25
Firefox MEDIUM 5.3
CVE-2020-6812

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera…

Fix: 68.6.0 / 74.0+
Fix from $1,600 2020-03-25
Firefox MEDIUM 5.3
CVE-2020-6813

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to injec…

Fix: 74.0+
Fix from $1,600 2020-03-25
Firefox HIGH 8.8
CVE-2020-6796

A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This coul…

Fix: 68.5.0 / 73.0+
Fix from $1,950 2020-03-02
Firefox HIGH 8.8
CVE-2020-6799

Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefo…

Fix: 68.5.0 / 73.0+
Fix from $1,950 2020-03-02
Firefox HIGH 8.8
CVE-2020-6800

Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence o…

Fix: 68.5.0 / 73.0+
Fix from $1,950 2020-03-02
Firefox HIGH 8.8
CVE-2020-6801

Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 73.0+
Fix from $1,950 2020-03-02
Firefox MEDIUM 6.1
CVE-2020-6798

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A …

Fix: 68.5.0 / 73.0+
Fix from $1,600 2020-03-02
Firefox HIGH 8.8
CVE-2019-17026 KEVEPSS 47%

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in …

Fix: 68.4.1 / 72.0.1+
Fix from $1,950 2020-03-02
Thunderbird MEDIUM 6.5
CVE-2020-6793

When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects T…

Fix: 68.5.0+
Fix from $1,600 2020-03-02
Thunderbird MEDIUM 6.5
CVE-2020-6795

When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to a…

Fix: 68.5.0+
Fix from $1,600 2020-03-02
Webthings Gateway MEDIUM 6.1
CVE-2020-6803

An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.

Fix: 2020-02-26+
Fix from $1,600 2020-02-28
Webthings Gateway MEDIUM 6.1
CVE-2020-6804

A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication …

Fix: 0.12.0+
Fix from $1,600 2020-02-28
Persona HIGH 8.8
CVE-2013-4227

Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x…

Fix: 7.x-1.11+
Fix from $1,950 2020-02-18
Firefox HIGH 8.8
CVE-2011-2668

Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header

Fix: after 1.5.0.3
Fix from $1,950 2020-01-21
Firefox MEDIUM 6.5
CVE-2011-2669

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

Fix: 3.6+
Fix from $1,600 2020-01-21
Firefox MEDIUM 6.1
CVE-2011-2670

Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets

Fix: 3.6+
Fix from $1,600 2020-01-13
Firefox CRITICAL 9.3
CVE-2019-9812

Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com …

Fix: 60.9 / 68.1+
Fix from $2,300 2020-01-08
Firefox HIGH 8.8
CVE-2019-17012

Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption an…

Fix: 68.3 / 71.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-17013

Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 71.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-17015

During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable cr…

Fix: 68.4 / 72.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-17017

Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort tha…

Fix: 68.4 / 72.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-17019

When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened…

Fix: 72.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-17024

Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption an…

Fix: 68.4 / 72.0+
Fix from $1,950 2020-01-08
Firefox HIGH 8.8
CVE-2019-17025

Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 72.0+
Fix from $1,950 2020-01-08
Firefox HIGH 7.4
CVE-2019-17014

If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-o…

Fix: 71.0+
Fix from $1,950 2020-01-08
Firefox MEDIUM 6.5
CVE-2019-17020

If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied …

Fix: 72.0+
Fix from $1,600 2020-01-08
Firefox MEDIUM 6.5
CVE-2019-17023

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS …

Fix: 72.0+
Fix from $1,600 2020-01-08