Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2016-1946EPSS 6%

The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operatio…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox HIGH 8.8
CVE-2016-1945

The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other…

Mitigation only
Fix from $1,950 2016-01-31
Firefox CRITICAL 9.8
CVE-2016-1944

The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of servic…

No fix yet
Fix from $2,300 2016-01-31
Firefox HIGH 7.4
CVE-2016-1942

Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a …

Fix: after 43.0.4
Fix from $1,950 2016-01-31
Firefox MEDIUM 6.1
CVE-2016-1941

The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickj…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 5.3
CVE-2016-1939

Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive informati…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 5.3
CVE-2016-1940

Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut openin…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 6.5
CVE-2016-1938

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, imprope…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 6.1
CVE-2016-1937

The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that trigge…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox MEDIUM 6.5
CVE-2016-1933

Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Firefox CRITICAL 10.0
CVE-2016-1931EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox CRITICAL 9.8
CVE-2016-1930EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to …

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox Os MEDIUM 6.4
CVE-2015-8511

Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requir…

Fix: after 2.2
Fix from $1,600 2016-01-09
Firefox Os MEDIUM 6.1
CVE-2015-8510

Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows us…

Fix: after 2.2
Fix from $1,600 2016-01-09
Firefox MEDIUM 5.9
CVE-2015-7575

Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject M…

Fix: after 43.0.1
Fix from $1,600 2016-01-09
Firefox MEDIUM 6.8
CVE-2015-7222

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox HIGH 10.0
CVE-2015-7221

Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause …

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox HIGH 10.0
CVE-2015-7220

Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of…

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7219

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, …

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7214EPSS 6%

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7211

Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox HIGH 7.5
CVE-2015-7210

Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by tri…

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7208

Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by readi…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7207

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass …

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox HIGH 10.0
CVE-2015-7203

Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allo…

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox HIGH 10.0
CVE-2015-7202EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory…

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox HIGH 7.5
CVE-2015-7200

The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lacks status checking, which allows attackers …

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 7.5
CVE-2015-7199

The (1) AddWeightedPathSegLists and (2) SVGPathSegListSMILType::Interpolate functions in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 7.5
CVE-2015-7198

Buffer overflow in the rx::TextureStorage11 class in ANGLE, as used in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, allows remote at…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox MEDIUM 5.0
CVE-2015-7197

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allow…

Fix: after 41.0.2
Fix from $1,600 2015-11-05