Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.3
CVE-2017-5426

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be ap…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5403

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after…

Fix: 52.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5413

A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Fix: 52.0+
Fix from $2,300 2018-06-11
Firefox HIGH 7.5
CVE-2017-5406

A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. …

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5411

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be free…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5412

A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird …

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5416

In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vuln…

Fix: 52.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-5409

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parame…

Fix: 45.8.0 / 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-5414

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to inform…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5415EPSS 13%

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furth…

Fix: 52.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5391

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found…

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5392

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruptio…

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5397

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for t…

Fix: 51.0.3+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5399

Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 52.0+
Fix from $2,300 2018-06-11
Firefox HIGH 8.8
CVE-2017-5394

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript even…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5381

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allow…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5382

Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal inform…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5385

Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to po…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5388

A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of tim…

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-5389

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.1
CVE-2017-5393

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow mal…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2017-5384

Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information tha…

Fix: 51.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5373

Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that wi…

Fix: 45.7.0 / 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5374

Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that…

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-5377

A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This …

Fix: 51.0+
Fix from $2,300 2018-06-11
Firefox HIGH 8.1
CVE-2016-9896

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Fi…

Fix: 50.1.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2017-5379

Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51.

Fix: 51.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.1
CVE-2016-9903

Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to b…

Fix: 50.1+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-9075

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This…

Fix: 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-9080

Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort th…

Fix: 50.1+
Fix from $2,300 2018-06-11