Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.5
CVE-2015-0835

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allow remote attackers to cause a denial of service (memory…

Fix: after 35.0.1
Fix from $1,950 2015-02-25
Firefox MEDIUM 6.9
CVE-2015-0833

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Firefox MEDIUM 6.8
CVE-2015-0831

Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x be…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Firefox MEDIUM 6.8
CVE-2015-0828

Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, …

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Firefox MEDIUM 6.8
CVE-2015-0826

The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a deni…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Firefox MEDIUM 6.8
CVE-2015-0821

Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Firefox HIGH 7.1
CVE-2014-8643

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging acce…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Firefox HIGH 7.5
CVE-2014-8641

Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 all…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Firefox MEDIUM 5.0
CVE-2014-8640

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey b…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Firefox MEDIUM 6.8
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Firefox MEDIUM 6.8
CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie he…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Firefox MEDIUM 5.0
CVE-2014-8637

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensi…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Firefox HIGH 7.5
CVE-2014-8636EPSS 66%

The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Firefox HIGH 7.5
CVE-2014-8635

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Firefox HIGH 7.5
CVE-2014-8634

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Network Security Services HIGH 7.5
CVE-2014-1569

The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does …

Fix: after 3.16.2.3
Fix from $1,950 2014-12-15
Firefox MEDIUM 6.8
CVE-2014-1594

Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1593

Stack-based buffer overflow in the mozilla::FileBlockCache::Read function in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird b…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1592

Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbir…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1589

Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypas…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1588

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 allow remote attackers to cause a…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1587

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and…

Fix: after 33.0
Fix from $1,600 2014-12-11
Firefox HIGH 7.6
CVE-2014-6492

Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20, when running on Firefox, allows remote attackers to affect confidentiality, integri…

Patch available
Fix from $1,950 2014-10-15
Firefox MEDIUM 5.0
CVE-2014-1585

The WebRTC video-sharing feature in dom/media/MediaManager.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x bef…

Fix: after 32.0
Fix from $1,600 2014-10-15
Firefox MEDIUM 5.0
CVE-2014-1586

content/base/src/nsDocument.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 does not consider whet…

Fix: after 32.0
Fix from $1,600 2014-10-15
Firefox HIGH 7.5
CVE-2014-1574

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before …

Fix: after 32.0
Fix from $1,950 2014-10-15
Firefox HIGH 7.5
CVE-2014-1575EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0 allow remote attackers to cause a denial of service (memory…

Fix: after 32.0
Fix from $1,950 2014-10-15
Firefox HIGH 7.5
CVE-2014-1576EPSS 5%

Heap-based buffer overflow in the nsTransformedTextRun function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x be…

Fix: after 32.0
Fix from $1,950 2014-10-15
Firefox HIGH 7.5
CVE-2014-1578

The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause…

Fix: after 32.0
Fix from $1,950 2014-10-15
Firefox HIGH 7.5
CVE-2014-1581

Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.…

Fix: after 32.0
Fix from $1,950 2014-10-15