Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 10.0
CVE-2018-18505

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and…

Fix: 60.5.0 / 65.0+
Fix from $2,300 2019-02-05
Firefox CRITICAL 9.8
CVE-2018-18500EPSS 13%

A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object…

Fix: 60.5 / 65.0+
Fix from $2,300 2019-02-05
Firefox CRITICAL 9.8
CVE-2018-18501

Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence o…

Fix: 60.5 / 65.0+
Fix from $2,300 2019-02-05
Firefox CRITICAL 9.8
CVE-2018-18502

Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption a…

Fix: 65.0+
Fix from $2,300 2019-02-05
Firefox CRITICAL 9.8
CVE-2018-18504

A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This result…

Fix: 65.0+
Fix from $2,300 2019-02-05
Firefox HIGH 8.8
CVE-2018-18503

When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some…

Fix: 65.0+
Fix from $1,950 2019-02-05
Firefox MEDIUM 5.9
CVE-2018-18506

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file …

Fix: 65.0+
Fix from $1,600 2019-02-05
Firefox CRITICAL 9.8
CVE-2018-5186

Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…

Fix: 61.0+
Fix from $2,300 2018-10-18
Firefox MEDIUM 5.3
CVE-2018-12381

Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrect…

Fix: 60.2.0 / 62.0+
Fix from $1,600 2018-10-18
Firefox MEDIUM 5.3
CVE-2018-12382

The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loade…

No fix yet
Fix from $1,600 2018-10-18
Firefox HIGH 8.8
CVE-2018-12375

Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…

Fix: 62.0+
Fix from $1,950 2018-10-18
Firefox CRITICAL 9.8
CVE-2018-12369

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu…

Fix: 60.1.0 / 61.0+
Fix from $2,300 2018-10-18
Firefox HIGH 8.1
CVE-2018-12368

Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the inte…

Fix: 52.9 / 60.1.0+
Fix from $1,950 2018-10-18
Firefox HIGH 8.8
CVE-2018-12361

An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computatio…

Fix: 60.0 / 60.1+
Fix from $1,950 2018-10-18
Firefox HIGH 7.8
CVE-2016-9069

A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Fir…

Fix: 50.0+
Fix from $1,950 2018-10-18
Network Security Services MEDIUM 5.9
CVE-2016-9574

nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.

Fix: 3.30+
Fix from $1,600 2018-07-19
Firefox HIGH 7.5
CVE-2018-5180

A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited…

Fix: 60.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5153

If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read …

Fix: 60.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5174

In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not…

Fix: 52.8.0 / 60.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5152

WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic…

Fix: 60.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2018-5164

Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This co…

Fix: 60.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5165

In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe F…

Fix: 60.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5151

Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 60.0+
Fix from $2,300 2018-06-11
Firefox HIGH 8.2
CVE-2018-5141

A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction.…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5134

WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that …

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5135

WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this sh…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5137

A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5132

The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a mali…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5133

If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2018-5143

URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a…

Fix: 59.0+
Fix from $1,600 2018-06-11