Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.8
CVE-2015-7196

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (inc…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox MEDIUM 5.0
CVE-2015-7195

The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which al…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox HIGH 7.5
CVE-2015-7194

Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to cause a denial of service (appl…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 7.5
CVE-2015-7193

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly follow the CORS cross-origin request algorithm for the POST method in situati…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 7.5
CVE-2015-7192

The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allow…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox MEDIUM 5.0
CVE-2015-7190

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access thi…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox MEDIUM 6.8
CVE-2015-7189

Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitra…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox HIGH 7.5
CVE-2015-7188

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and co…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 7.5
CVE-2015-7183EPSS 7%

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox CRITICAL 9.8
CVE-2015-7182EPSS 10%

Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firef…

Fix: after 41.0.2
Fix from $2,300 2015-11-05
Firefox HIGH 7.5
CVE-2015-7181EPSS 8%

The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 7.5
CVE-2015-4514

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remote attackers to cause a denial of service (memory…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox HIGH 7.5
CVE-2015-4513

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to …

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Firefox MEDIUM 6.8
CVE-2015-7184

The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user cre…

Fix: after 41.0.1
Fix from $1,600 2015-10-18
Firefox HIGH 7.5
CVE-2015-7180

The ReadbackResultWriterD3D11::Run function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 misinterprets the return value of a funct…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7179

The VertexBufferInterface::reserveVertexSpace function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 o…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7178

The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, m…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7176

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7177

The InitTextures function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7175

The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a deni…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7174

The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a deni…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-4522

The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a de…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-4521

The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of s…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox MEDIUM 6.4
CVE-2015-4520

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) …

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox HIGH 7.5
CVE-2015-4517

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory co…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 9.3
CVE-2015-4516

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable propertie…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox MEDIUM 6.4
CVE-2015-4512

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface cr…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 6.8
CVE-2015-4511

Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote att…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 6.8
CVE-2015-4510

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or caus…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox HIGH 7.5
CVE-2015-4509EPSS 6%

Use-after-free vulnerability in the HTMLVideoElement interface in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attacker…

Fix: after 40.0.3
Fix from $1,950 2015-09-24