Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2017-7773

Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Firefox HIGH 8.8
CVE-2017-7777

Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Firefox HIGH 8.1
CVE-2017-7771

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Firefox HIGH 8.1
CVE-2017-7776

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Firefox HIGH 8.8
CVE-2017-7772

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-12
Firefox CRITICAL 9.8
CVE-2018-12405

Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence o…

Fix: 60.4.0 / 64.0+
Fix from $2,300 2019-02-28
Firefox CRITICAL 9.8
CVE-2018-12407

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBu…

Fix: 64.0+
Fix from $2,300 2019-02-28
Firefox CRITICAL 9.8
CVE-2018-18492EPSS 10%

A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. …

Fix: 60.4.0 / 64.0+
Fix from $2,300 2019-02-28
Firefox CRITICAL 9.8
CVE-2018-18493

A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bi…

Fix: 60.4.0 / 64.0+
Fix from $2,300 2019-02-28
Firefox CRITICAL 9.8
CVE-2018-18498

A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the…

Fix: 60.4 / 64.0+
Fix from $2,300 2019-02-28
Firefox HIGH 8.8
CVE-2018-12406

Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption a…

Fix: 64.0+
Fix from $1,950 2019-02-28
Firefox HIGH 8.8
CVE-2018-18496

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack t…

Fix: 64.0+
Fix from $1,950 2019-02-28
Firefox HIGH 7.5
CVE-2018-12401

Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lea…

Fix: 63.0+
Fix from $1,950 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-12402

The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as p…

Fix: 63.0+
Fix from $1,600 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-18494

A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to a…

Fix: 60.4.0 / 64.0+
Fix from $1,600 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-18495

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could…

Fix: 64.0+
Fix from $1,600 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-18497

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the ex…

Fix: 64.0+
Fix from $1,600 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-18499

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection…

Fix: 60.2 / 60.2.1+
Fix from $1,600 2019-02-28
Firefox MEDIUM 5.3
CVE-2018-12400

In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati…

Fix: 63.0+
Fix from $1,600 2019-02-28
Firefox MEDIUM 5.3
CVE-2018-12403

If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnera…

Fix: 63.0+
Fix from $1,600 2019-02-28
Firefox CRITICAL 9.8
CVE-2018-12390

Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence o…

Fix: 60.3.0 / 63.0+
Fix from $2,300 2019-02-28
Firefox CRITICAL 9.8
CVE-2018-12392

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due …

Fix: 60.3.0 / 63.0+
Fix from $2,300 2019-02-28
Firefox HIGH 8.8
CVE-2018-12388

Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption a…

Fix: 63.0+
Fix from $1,950 2019-02-28
Firefox HIGH 8.8
CVE-2018-12389

Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corrup…

Fix: 60.3.0+
Fix from $1,950 2019-02-28
Firefox HIGH 8.8
CVE-2018-12391

During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro…

Fix: 60.3 / 63.0+
Fix from $1,950 2019-02-28
Firefox HIGH 7.5
CVE-2018-12393

A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation …

Fix: 60.3 / 63.0+
Fix from $1,950 2019-02-28
Firefox HIGH 7.5
CVE-2018-12395

By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would al…

Fix: 60.3 / 63.0+
Fix from $1,950 2019-02-28
Firefox HIGH 7.1
CVE-2018-12397

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being…

Fix: 60.3.0 / 63.0+
Fix from $1,950 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-12396

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential p…

Fix: 60.3 / 63.0+
Fix from $1,600 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-12398

By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (C…

Fix: 63.0+
Fix from $1,600 2019-02-28