Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.3
CVE-2018-5138

A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel insid…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5140

Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow f…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5142

If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly di…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5116

WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious e…

Fix: after 57.0.4
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5122

A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-…

Fix: after 57.0.4
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5126

Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 59.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5128

A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potenti…

Fix: 59.0+
Fix from $2,300 2018-06-11
Firefox HIGH 7.8
CVE-2018-5105

WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with …

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5112

Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirem…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5113

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properl…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5115

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded for…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5111

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site …

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5106

Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5107

The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing pr…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5109

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the reques…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5110

If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible wi…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5114

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document …

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5118

The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue wa…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5119

The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could all…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5121

Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an International…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5090

Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: after 57.0.4
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2018-5092

A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread …

Fix: after 57.0.4
Fix from $2,300 2018-06-11
Firefox HIGH 8.8
CVE-2017-7845

A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due …

Fix: 52.5.2 / 57.0.2+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5093EPSS 20%

A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulner…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5094EPSS 15%

A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that is now un…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5100EPSS 5%

A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. Thi…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5101

A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7827

Memory safety bugs were reported in Firefox 56. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: after 56.0.2
Fix from $2,300 2018-06-11
Firefox HIGH 7.8
CVE-2017-7836

The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allow…

Fix: after 56.0.2
Fix from $1,950 2018-06-11
Firefox HIGH 7.3
CVE-2017-7835

Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resources that redirect from HTTPS…

Fix: after 56.0.2
Fix from $1,950 2018-06-11