Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.0
CVE-2014-1500

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang)…

Fix: 2.25 / 28.0+
Fix from $1,600 2014-03-19
Firefox MEDIUM 6.8
CVE-2013-6167

Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows re…

Fix: after 27.0
Fix from $1,600 2014-02-15
Firefox HIGH 10.0
CVE-2014-1488EPSS 7%

The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors…

Fix: 2.24 / 27.0+
Fix from $1,950 2014-02-06
Firefox HIGH 9.3
CVE-2014-1490

Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24…

Fix: 2.24 / 3.15.4+
Fix from $1,950 2014-02-06
Firefox HIGH 7.5
CVE-2014-1487

The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow…

Fix: 24.3 / 27.0+
Fix from $1,950 2014-02-06
Firefox HIGH 10.0
CVE-2014-1478EPSS 7%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a…

Fix: 2.24 / 27.0+
Fix from $1,950 2014-02-06
Firefox CRITICAL 9.8
CVE-2014-1477EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and…

Fix: 24.3 / 27.0+
Fix from $2,300 2014-02-06
Firefox CRITICAL 9.8
CVE-2014-1486EPSS 7%

Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, a…

Fix: 24.3 / 27.0+
Fix from $2,300 2014-02-06
Firefox HIGH 8.8
CVE-2014-1482EPSS 6%

RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent acc…

Fix: 24.3 / 27.0+
Fix from $1,950 2014-02-06
Firefox HIGH 7.5
CVE-2014-1479

The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey bef…

Fix: 24.3 / 27.0+
Fix from $1,950 2014-02-06
Firefox HIGH 7.5
CVE-2014-1481

Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intend…

Fix: 24.3 / 27.0+
Fix from $1,950 2014-02-06
Firefox HIGH 7.5
CVE-2014-1485

The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to s…

Fix: 2.24 / 27.0+
Fix from $1,950 2014-02-06
Firefox MEDIUM 5.0
CVE-2014-1484

Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitiv…

Fix: after 26.0
Fix from $1,600 2014-02-06
Network Security Services MEDIUM 5.8
CVE-2013-1740

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is…

Fix: after 3.15.3
Fix from $1,600 2014-01-18
Firefox CRITICAL 9.8
CVE-2013-5618EPSS 10%

Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox …

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-6671EPSS 11%

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox HIGH 7.5
CVE-2013-5619

Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow r…

Fix: 2.23 / 26.0+
Fix from $1,950 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5613EPSS 9%

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderb…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5615

The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does n…

Fix: 2.23 / 24.2+
Fix from $2,300 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5616EPSS 7%

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2,…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox HIGH 10.0
CVE-2013-5610EPSS 7%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a…

Fix: 2.23 / 26.0+
Fix from $1,950 2013-12-11
Firefox CRITICAL 9.8
CVE-2013-5609EPSS 8%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and…

Fix: 24.2 / 26.0+
Fix from $2,300 2013-12-11
Firefox HIGH 7.5
CVE-2013-5607

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefo…

Fix: after 4.10.1
Fix from $1,950 2013-11-20
Network Security Services HIGH 7.5
CVE-2013-1741

Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have …

Mitigation only
Fix from $1,950 2013-11-18
Network Security Services HIGH 7.5
CVE-2013-5605

Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly ha…

Patch available
Fix from $1,950 2013-11-18
Network Security Services MEDIUM 5.8
CVE-2013-5606

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return va…

Mitigation only
Fix from $1,600 2013-11-18
Firefox HIGH 10.0
CVE-2013-5590EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thun…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 10.0
CVE-2013-5591

Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey …

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 10.0
CVE-2013-5592EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0 allow remote attackers to cause a denial of service (memory…

Fix: after 24.0
Fix from $1,950 2013-10-30
Firefox HIGH 10.0
CVE-2013-5597EPSS 6%

Use-after-free vulnerability in the nsDocLoader::doStopDocumentLoad function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x…

Fix: after 24.0.1
Fix from $1,950 2013-10-30