Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.5
CVE-2015-2728

The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox MEDIUM 6.8
CVE-2015-2727

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chro…

Mitigation only
Fix from $1,600 2015-07-06
Firefox HIGH 10.0
CVE-2015-2726EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0 allow remote attackers to cause a denial of service (memory…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2725EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 …

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2724EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thu…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox HIGH 10.0
CVE-2015-2722EPSS 6%

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x be…

Fix: after 38.1.0
Fix from $1,950 2015-07-06
Firefox MEDIUM 6.8
CVE-2015-2717

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (hea…

Fix: after 37.0.2
Fix from $1,600 2015-05-14
Firefox HIGH 7.5
CVE-2015-2716EPSS 7%

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers t…

Fix: after 37.0.2
Fix from $1,950 2015-05-14
Firefox MEDIUM 6.8
CVE-2015-2715

Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary cod…

Fix: after 37.0.2
Fix from $1,600 2015-05-14
Firefox MEDIUM 6.8
CVE-2015-2713

Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allo…

Fix: after 37.0.2
Fix from $1,600 2015-05-14
Firefox HIGH 7.5
CVE-2015-2712

The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during identification of cases in which bounds chec…

Fix: after 37.0.2
Fix from $1,950 2015-05-14
Firefox MEDIUM 6.8
CVE-2015-2710

Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows…

Fix: after 37.0.2
Fix from $1,600 2015-05-14
Firefox HIGH 7.5
CVE-2015-2709

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory…

Fix: after 37.0.2
Fix from $1,950 2015-05-14
Firefox HIGH 7.5
CVE-2015-2708

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 …

Fix: after 37.0.2
Fix from $1,950 2015-05-14
Firefox MEDIUM 6.8
CVE-2015-0797EPSS 5%

GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote att…

Fix: 31.7 / 38.0+
Fix from $1,600 2015-05-14
Firefox MEDIUM 6.8
CVE-2015-2706

Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary…

Fix: after 37.0.1
Fix from $1,600 2015-04-27
Firefox MEDIUM 5.0
CVE-2015-0798

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which…

Fix: after 37.0
Fix from $1,600 2015-04-08
Firefox MEDIUM 5.0
CVE-2015-0816EPSS 67%

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox HIGH 7.5
CVE-2015-0814

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory…

Mitigation only
Fix from $1,950 2015-04-01
Firefox HIGH 7.5
CVE-2015-0815

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 …

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Firefox MEDIUM 5.1
CVE-2015-0813EPSS 5%

Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox MEDIUM 6.4
CVE-2015-0811

The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a de…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox MEDIUM 6.8
CVE-2015-0807

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x …

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox HIGH 7.5
CVE-2015-0805

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozil…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Firefox HIGH 7.5
CVE-2015-0804

The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Firefox HIGH 7.5
CVE-2015-0801

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and ex…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Firefox MEDIUM 5.0
CVE-2015-0800

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for quer…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox HIGH 7.5
CVE-2015-0818

Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy an…

Fix: after 36.0.3
Fix from $1,950 2015-03-24
Firefox MEDIUM 6.8
CVE-2015-0817

The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine t…

Fix: after 36.0.1
Fix from $1,600 2015-03-24
Firefox HIGH 7.5
CVE-2015-0836

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 …

Fix: after 35.0.1
Fix from $1,950 2015-02-25