Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.0
CVE-2014-1539

Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a D…

Fix: after 29.0.1
Fix from $1,600 2014-06-11
Firefox CRITICAL 9.8
CVE-2014-1532

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x…

Fix: 24.5 / 29.0+
Fix from $2,300 2014-04-30
Firefox HIGH 8.8
CVE-2014-1531EPSS 6%

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.…

Fix: 24.5 / 29.0+
Fix from $1,950 2014-04-30
Firefox MEDIUM 6.1
CVE-2014-1530

The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows r…

Fix: 24.5 / 29.0+
Fix from $1,600 2014-04-30
Firefox CRITICAL 9.8
CVE-2014-1524EPSS 8%

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonk…

Fix: 24.5 / 29.0+
Fix from $2,300 2014-04-30
Firefox HIGH 9.3
CVE-2014-1519

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allow remote attackers to cause a…

Fix: 2.26 / 29.0+
Fix from $1,950 2014-04-30
Firefox HIGH 9.3
CVE-2014-1525

The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection fo…

Fix: 2.26 / 29.0+
Fix from $1,950 2014-04-30
Firefox HIGH 8.8
CVE-2014-1518EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and…

Fix: 24.5 / 29.0+
Fix from $1,950 2014-04-30
Firefox HIGH 8.8
CVE-2014-1529

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remo…

Fix: 24.5 / 29.0+
Fix from $1,950 2014-04-30
Firefox MEDIUM 6.9
CVE-2014-1520

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows l…

Fix: 24.5 / 29.0+
Fix from $1,600 2014-04-30
Firefox MEDIUM 6.8
CVE-2014-1526

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended acce…

Fix: 2.26 / 29.0+
Fix from $1,600 2014-04-30
Firefox MEDIUM 6.5
CVE-2014-1523

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMon…

Fix: 24.5 / 29.0+
Fix from $1,600 2014-04-30
Firefox MEDIUM 5.0
CVE-2014-1516

The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to s…

Fix: after 28.0.1
Fix from $1,600 2014-03-29
Firefox HIGH 10.0
CVE-2014-1512EPSS 31%

Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbi…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1493EPSS 8%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1510EPSS 82%

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows re…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1511EPSS 84%

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the po…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1514EPSS 6%

vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not vali…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox HIGH 9.3
CVE-2014-1494EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a…

Fix: 2.25 / 28.0+
Fix from $1,950 2014-03-19
Firefoxos HIGH 9.3
CVE-2014-1507

Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection …

Fix: after 1.2
Fix from $1,950 2014-03-19
Firefox CRITICAL 9.1
CVE-2014-1508

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey befor…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox HIGH 8.8
CVE-2014-1497

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonke…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox HIGH 8.8
CVE-2014-1509EPSS 5%

Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunder…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox HIGH 8.8
CVE-2014-1513EPSS 6%

TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not preven…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox HIGH 7.5
CVE-2014-1505

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox MEDIUM 6.8
CVE-2014-1502

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow rem…

Fix: 2.25 / 28.0+
Fix from $1,600 2014-03-19
Firefox MEDIUM 6.4
CVE-2014-1506

Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of…

Fix: after 27.0.1
Fix from $1,600 2014-03-19
Firefox MEDIUM 5.8
CVE-2014-1501

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving…

Fix: after 27.0.1
Fix from $1,600 2014-03-19
Firefox MEDIUM 5.5
CVE-2014-1496

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privile…

Fix: 2.25 / 24.4+
Fix from $1,600 2014-03-19
Firefox MEDIUM 5.0
CVE-2014-1498

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which a…

Fix: 2.25 / 28.0+
Fix from $1,600 2014-03-19