Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 8.8
CVE-2016-2805

Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory …

Mitigation only
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2804

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2802

The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x b…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2800

The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2798

The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2794

The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2792

The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2791

The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-2790

The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, do…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1979

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as us…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 7.3
CVE-2016-1978

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozi…

Fix: after 43.0.4
Fix from $1,950 2016-03-13
Firefox MEDIUM 5.5
CVE-2016-1976

Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow rem…

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Firefox MEDIUM 6.3
CVE-2016-1975

Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might al…

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Firefox HIGH 8.8
CVE-2016-1974

The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1972

Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or poss…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1971

The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, wh…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1970

Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1969

The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers t…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1968

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox MEDIUM 6.5
CVE-2016-1967

Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass …

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Firefox HIGH 7.4
CVE-2016-1963

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changin…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox CRITICAL 9.8
CVE-2016-1962EPSS 6%

Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 al…

Fix: after 44.0.2
Fix from $2,300 2016-03-13
Firefox HIGH 8.8
CVE-2016-1961

Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1959

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox MEDIUM 6.5
CVE-2016-1956

Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or…

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Firefox HIGH 8.8
CVE-2016-1954

The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prev…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1953

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1950

Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1949

Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass…

Fix: after 44.0.1
Fix from $1,950 2016-02-13
Firefox MEDIUM 5.3
CVE-2016-1948

Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attack…

Mitigation only
Fix from $1,600 2016-01-31