Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.1
CVE-2015-4507

The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to c…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 6.8
CVE-2015-4506

Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows r…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 6.6
CVE-2015-4505

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 6.4
CVE-2015-4504

The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 5.0
CVE-2015-4503

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox HIGH 7.5
CVE-2015-4501

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 allow remote attackers to cause a denial of service (memory…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-4500

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to …

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Bugzilla HIGH 7.5
CVE-2015-4499

Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during acco…

Patch available
Fix from $1,950 2015-09-14
Firefox HIGH 7.5
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended use…

Fix: after 40.0.2
Fix from $1,950 2015-08-29
Firefox HIGH 10.0
CVE-2015-4497EPSS 8%

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allow…

Mitigation only
Fix from $1,950 2015-08-29
Firefox HIGH 9.3
CVE-2015-4496

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metad…

Fix: after 37.0.2
Fix from $1,950 2015-08-16
Firefox HIGH 9.3
CVE-2015-4493EPSS 7%

Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox HIGH 7.5
CVE-2015-4492EPSS 5%

Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow r…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox HIGH 7.5
CVE-2015-4489

The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox HIGH 7.5
CVE-2015-4487

The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote att…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox HIGH 10.0
CVE-2015-4485EPSS 8%

Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows re…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox HIGH 10.0
CVE-2015-4479EPSS 9%

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitr…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox HIGH 7.5
CVE-2015-4475

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 aud…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox Os MEDIUM 5.0
CVE-2015-5962

Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics…

Fix: after 2.1.0
Fix from $1,600 2015-08-08
Firefox HIGH 8.8
CVE-2015-4495 KEVEPSS 69%

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same…

Fix: 2.2 / 38.1.1+
Fix from $1,950 2015-08-08
Firefox HIGH 7.5
CVE-2015-2743

PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which …

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2740EPSS 6%

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 3…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2739

The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2737

The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before …

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 9.3
CVE-2015-2736

The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 9.3
CVE-2015-2735

nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended m…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2734

The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 a…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2731EPSS 6%

Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x …

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2733EPSS 6%

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x be…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox MEDIUM 5.0
CVE-2015-2729

The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 …

Fix: after 38.1.0
Fix from $1,600 2015-07-06