Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 10.0
CVE-2013-5599EPSS 5%

Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 10.0
CVE-2013-5600EPSS 5%

Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 10.0
CVE-2013-5601EPSS 5%

Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 …

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 10.0
CVE-2013-5602EPSS 5%

The Worker::SetEventListener function in the Web workers implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x befo…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 10.0
CVE-2013-5603EPSS 5%

Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x befo…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 9.3
CVE-2013-5604EPSS 6%

The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1,…

Fix: after 24.0.1
Fix from $1,950 2013-10-30
Firefox HIGH 8.3
CVE-2013-5598

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remo…

Fix: after 24.0
Fix from $1,950 2013-10-30
Firefox MEDIUM 6.8
CVE-2013-5596

The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before …

Fix: after 24.0.1
Fix from $1,600 2013-10-30
Bugzilla MEDIUM 6.8
CVE-2013-1734

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.…

Patch available
Fix from $1,600 2013-10-24
Bugzilla MEDIUM 6.8
CVE-2013-1733

Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authenticatio…

Patch available
Fix from $1,600 2013-10-24
Network Security Services MEDIUM 5.0
CVE-2013-1739

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remot…

Fix: after 3.15.1
Fix from $1,600 2013-10-22
Firefox HIGH 10.0
CVE-2013-1719EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow r…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 10.0
CVE-2013-1736EPSS 5%

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1721

Integer overflow in the drawLineLoop function in the libGLESv2 library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox bef…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1722EPSS 6%

Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1724EPSS 6%

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1732EPSS 9%

Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, …

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1735

Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thund…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox HIGH 9.3
CVE-2013-1738EPSS 6%

Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before …

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1720

The nsHtml5TreeBuilder::resetTheInsertionMode function in the HTML5 Tree Builder in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonk…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1725

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1730

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 6.8
CVE-2013-1731

Untrusted search path vulnerability in the GL tracing functionality in Mozilla Firefox before 24.0 on Android allows attackers to execute arbitrary c…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 6.2
CVE-2013-1726

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaM…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 5.0
CVE-2013-1737

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox HIGH 10.0
CVE-2013-1718EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, T…

Fix: after 23.0.1
Fix from $1,950 2013-09-18
Firefox MEDIUM 5.4
CVE-2013-1717

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20…

Fix: after 22.0
Fix from $1,600 2013-08-07
Firefox HIGH 10.0
CVE-2013-1701

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8,…

Fix: after 22.0
Fix from $1,950 2013-08-07
Firefox HIGH 10.0
CVE-2013-1702EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a…

Fix: after 22.0
Fix from $1,950 2013-08-07
Firefox HIGH 10.0
CVE-2013-1705

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type function in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allows remote at…

Fix: after 22.0
Fix from $1,950 2013-08-07