Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Network Security Services MEDIUM 5.9
CVE-2018-12384

When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This result…

Fix: 3.39+
Fix from $1,600 2019-04-29
Firefox HIGH 8.8
CVE-2019-9810EPSS 30%

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This v…

Fix: 60.6.1 / 66.0.1+
Fix from $1,950 2019-04-26
Firefox HIGH 8.8
CVE-2019-9813EPSS 7%

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. …

Fix: 60.6.1 / 66.0.1+
Fix from $1,950 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9804

In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the executio…

Fix: 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9805

A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory co…

Fix: 66.0+
Fix from $2,300 2019-04-26
Firefox HIGH 7.5
CVE-2019-9802

If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The d…

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox HIGH 7.5
CVE-2019-9806

A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dism…

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox HIGH 7.5
CVE-2019-9809

If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources th…

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox HIGH 7.4
CVE-2019-9803

The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin UR…

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox MEDIUM 5.3
CVE-2019-9808

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domai…

Fix: 66.0+
Fix from $1,600 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9794

A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9795

A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a pote…

Fix: 60.6 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9796

A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single re…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox HIGH 7.5
CVE-2019-9799

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the …

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox HIGH 7.4
CVE-2019-9798

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third p…

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox MEDIUM 5.3
CVE-2019-9797

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then…

Fix: 66.0+
Fix from $1,600 2019-04-26
Firefox MEDIUM 5.3
CVE-2019-9801

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on…

Fix: 60.6 / 66.0+
Fix from $1,600 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9788

Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bug…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9789

Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption a…

Fix: 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9790

A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed w…

Fix: after 66.0
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9791EPSS 20%

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonM…

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox CRITICAL 9.8
CVE-2019-9792EPSS 13%

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value …

Fix: 60.6.0 / 66.0+
Fix from $2,300 2019-04-26
Firefox MEDIUM 5.9
CVE-2019-9793

A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. Th…

Fix: 60.6 / 66.0+
Fix from $1,600 2019-04-26
Thunderbird CRITICAL 9.8
CVE-2018-18512

A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediately freed, a…

Fix: 65.0+
Fix from $2,300 2019-04-26
Thunderbird HIGH 7.5
CVE-2018-18513

A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service …

Fix: 60.5.0+
Fix from $1,950 2019-04-26
Firefox MEDIUM 6.5
CVE-2018-18510

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for …

Fix: 64.0+
Fix from $1,600 2019-04-26
Firefox MEDIUM 6.1
CVE-2018-5124

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

Fix: 58.0.1+
Fix from $1,600 2019-04-26
Thunderbird MEDIUM 5.3
CVE-2018-18509

A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the sho…

Fix: 60.5.1+
Fix from $1,600 2019-04-26
Firefox HIGH 7.5
CVE-2018-5179

A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Aff…

Fix: 60.0+
Fix from $1,950 2019-04-26
Firefox CRITICAL 9.1
CVE-2017-7774

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

Fix: 1.3.10 / 54.0+
Fix from $2,300 2019-04-15