Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2016-9078

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in…

Patch available
Fix from $1,950 2018-06-11
Firefox HIGH 8.0
CVE-2016-9070

A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operati…

Fix: 50+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9065

The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location …

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9066EPSS 12%

A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vul…

Fix: 45.5.0 / 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9068

A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox <…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9072

When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This iss…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9073

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox …

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9894EPSS 5%

A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buffer, resulting in a potential…

Fix: 50.1+
Fix from $1,950 2018-06-11
Firefox HIGH 7.0
CVE-2016-9077

Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-9067

Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-9064

Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perfor…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-9074

An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NS…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-9076

An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e1…

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2016-9071

Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's bro…

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5287

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefo…

Fix: 49.0.2+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5289

Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s…

Fix: 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5290

Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 45.5.0 / 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-5297

An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affect…

Fix: 45.5.0 / 50.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-9063EPSS 5%

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Fix: 2.7.15 / 3.3.7+
Fix from $2,300 2018-06-11
Firefox HIGH 7.8
CVE-2016-5295

This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozil…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-5296

A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulne…

Fix: 45.5.0 / 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-5299

A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9061

A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant f…

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5292

During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2016-5298

A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when the new pa…

Fix: 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.9
CVE-2016-5288

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This i…

Fix: 49.0.2+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5291

A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firef…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5293

When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local …

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.5
CVE-2016-5294

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerabilit…

Fix: 45.5.0 / 50.0+
Fix from $1,600 2018-06-11
Nunjucks MEDIUM 6.1
CVE-2016-10547

Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape …

Fix: after 2.4.2
Fix from $1,600 2018-05-31