Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bleach CRITICAL 9.8
CVE-2018-7753

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character en…

Patch available
Fix from $2,300 2018-03-07
Network Security Services HIGH 7.8
CVE-2017-11695

Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attac…

No fix yet
Fix from $1,950 2017-12-27
Network Security Services HIGH 7.8
CVE-2017-11696

Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent atta…

No fix yet
Fix from $1,950 2017-12-27
Network Security Services HIGH 7.8
CVE-2017-11697

The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (fl…

No fix yet
Fix from $1,950 2017-12-27
Network Security Services HIGH 7.8
CVE-2017-11698

Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent att…

No fix yet
Fix from $1,950 2017-12-27
Firefox CRITICAL 9.8
CVE-2007-5341

Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.

Fix: after 2.0.0.7
Fix from $2,300 2017-08-18
Network Security Services HIGH 7.5
CVE-2017-7502

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re…

Patch available
Fix from $1,950 2017-05-30
Network Security Services CRITICAL 9.8
CVE-2017-5461

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows rem…

Fix: 3.21.4 / 3.28.4+
Fix from $2,300 2017-05-11
Bugzilla MEDIUM 6.1
CVE-2016-2803

Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers…

No fix yet
Fix from $1,600 2017-04-12
Firefox HIGH 8.8
CVE-2016-5283

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFR…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 7.4
CVE-2016-5284

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinnin…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox MEDIUM 6.5
CVE-2016-5282

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive informa…

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5281EPSS 5%

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows re…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5280EPSS 5%

Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 4…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox HIGH 8.8
CVE-2016-5278

Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird …

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5277

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5276

Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x b…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox HIGH 8.8
CVE-2016-5275

Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to exe…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5274

Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thun…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox HIGH 8.8
CVE-2016-5273

The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote atta…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 8.8
CVE-2016-5272

The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast …

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox MEDIUM 6.5
CVE-2016-5271

The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds …

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5270

Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5257

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow …

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5256

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox MEDIUM 6.5
CVE-2016-2827

The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds r…

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Netscape Portable Runtime HIGH 8.6
CVE-2016-1951

Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service …

Fix: after 4.11
Fix from $1,950 2016-08-07
Firefox MEDIUM 5.3
CVE-2016-5267

Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-l…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 8.1
CVE-2016-5266

Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote att…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-5264

Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 4…

Fix: after 47.0.1
Fix from $1,950 2016-08-05