Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2017-7756

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially e…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7757

A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7778EPSS 5%

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninit…

Fix: 1.3.10 / 52.2.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7780

Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 55.0+
Fix from $2,300 2018-06-11
Firefox HIGH 7.8
CVE-2017-7760

The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original f…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.8
CVE-2017-7766

An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-7759

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of l…

Fix: 54.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-7765

The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the W…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.9
CVE-2017-7770

A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This w…

Fix: 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2017-7781

An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can yield a result "POINT_AT_INFI…

Fix: 55.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7761

The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with c…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7767

The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater,…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the s…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7763

Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name s…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7764

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rend…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7782

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. No…

Fix: 52.3.0 / 55.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5471

Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.1
CVE-2017-5468

An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash …

Fix: 53.0+
Fix from $2,300 2018-06-11
Firefox HIGH 7.8
CVE-2017-7755

The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows pr…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5463

Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of …

Fix: 53.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5450

A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, mak…

Fix: 53.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-5458

When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socia…

Fix: 53.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2017-5419

If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown throu…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5421

A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is curre…

Fix: 52.0.+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5422

If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the h…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5425

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some da…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2017-5420

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker t…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-5427

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local …

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5417

When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displa…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5418

An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of ran…

Fix: 52.0+
Fix from $1,600 2018-06-11