Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2016-5263

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, whic…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox MEDIUM 6.1
CVE-2016-5262

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRA…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 8.8
CVE-2016-5261

Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 and Firefox ESR < 45.4 allows remote attack…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox MEDIUM 6.5
CVE-2016-5260

Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which mig…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 8.8
CVE-2016-5259

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remo…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-5255

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbi…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox CRITICAL 9.8
CVE-2016-5254

Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attack…

Fix: after 47.0.1
Fix from $2,300 2016-08-05
Firefox MEDIUM 6.5
CVE-2016-2839

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with …

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 8.8
CVE-2016-2838

Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows rem…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox MEDIUM 6.3
CVE-2016-2837

Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 8.8
CVE-2016-2836

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to …

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-2835

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox MEDIUM 6.1
CVE-2016-2833

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attacker…

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Firefox HIGH 7.8
CVE-2016-2826

The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification d…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2824

The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to …

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 7.5
CVE-2016-2821

Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2819EPSS 24%

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via fore…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2818

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to …

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2815

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox CRITICAL 9.8
CVE-2016-0718EPSS 13%

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, whic…

Fix: 2.7.15 / 3.3.7+
Fix from $2,300 2016-05-26
Firefox MEDIUM 5.4
CVE-2016-2817

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inh…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 6.5
CVE-2016-2816

Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replac…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox HIGH 8.8
CVE-2016-2814

Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ES…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox MEDIUM 6.5
CVE-2016-2813

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to …

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox HIGH 7.5
CVE-2016-2812

Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remo…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2811

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox MEDIUM 5.0
CVE-2016-2810

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that le…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 5.5
CVE-2016-2809

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by …

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox HIGH 7.5
CVE-2016-2808

The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allo…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2807

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before …

Fix: after 45.0.2
Fix from $1,950 2016-04-30