Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.5
CVE-2012-5836

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote attackers to execute arbitrary code or cause a denial of…

Fix: 2.14 / 17.0+
Fix from $1,950 2012-11-21
Firefox MEDIUM 6.8
CVE-2012-5837

The Web Developer Toolbar in Mozilla Firefox before 17.0 executes script with chrome privileges, which allows user-assisted remote attackers to condu…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Firefox HIGH 10.0
CVE-2012-4212EPSS 6%

Use-after-free vulnerability in the XPCWrappedNative::Mark function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.1…

Fix: 2.14 / 17.0+
Fix from $1,950 2012-11-21
Firefox HIGH 10.0
CVE-2012-4218EPSS 6%

Use-after-free vulnerability in the BuildTextRunsScanner::BreakSink::SetBreaks function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and …

Fix: 2.14 / 17.0+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4210

The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Casc…

Fix: after 16.0.2
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4213EPSS 6%

Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4214EPSS 6%

Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunde…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4215EPSS 6%

Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, T…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4216EPSS 6%

Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird befor…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4217EPSS 6%

Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMon…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4202EPSS 11%

Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbi…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21
Firefox HIGH 9.3
CVE-2012-4204EPSS 6%

The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote a…

Fix: 2.14 / 17.0+
Fix from $1,950 2012-11-21
Firefox MEDIUM 6.9
CVE-2012-4206

Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Firefox MEDIUM 6.8
CVE-2012-4203

The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assiste…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Firefox MEDIUM 6.8
CVE-2012-4205

Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XM…

Fix: 2.14 / 17.0+
Fix from $1,600 2012-11-21
Bugzilla MEDIUM 5.0
CVE-2012-4197

Bugzilla/Attachment.pm in attachment.cgi in Bugzilla 2.x and 3.x before 3.6.12, 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x…

Patch available
Fix from $1,600 2012-11-16
Bugzilla MEDIUM 5.0
CVE-2012-5884

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches…

Mitigation only
Fix from $1,600 2012-11-16
Zamboni HIGH 7.4
CVE-2012-5822

The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,950 2012-11-04
Firefox MEDIUM 6.4
CVE-2012-4196

Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before …

Fix: 2.13.2 / 10.0.10+
Fix from $1,600 2012-10-29
Firefox HIGH 10.0
CVE-2012-4190

The FT2FontEntry::CreateFontEntry function in FreeType, as used in the Android build of Mozilla Firefox before 16.0.1 on CyanogenMod 10, allows remot…

Fix: after 16.0
Fix from $1,950 2012-10-12
Firefox HIGH 9.3
CVE-2012-4191

The mozilla::net::FailDelayManager::Lookup function in the WebSockets implementation in Mozilla Firefox before 16.0.1, Thunderbird before 16.0.1, and…

Fix: 2.13.1 / 16.0.1+
Fix from $1,950 2012-10-12
Firefox MEDIUM 6.8
CVE-2012-4193

Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.…

Fix: 2.13.1 / 10.0.9+
Fix from $1,600 2012-10-12
Firefox HIGH 9.3
CVE-2012-3993EPSS 43%

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird E…

Fix: after 15.0.1
Fix from $1,950 2012-10-10
Firefox HIGH 9.3
CVE-2012-3995EPSS 5%

The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x befo…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Firefox HIGH 9.3
CVE-2012-4179

Use-after-free vulnerability in the nsHTMLCSSUtils::CreateCSSPropertyTxn function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thu…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Firefox HIGH 9.3
CVE-2012-4180EPSS 9%

Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, T…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Firefox HIGH 9.3
CVE-2012-4181

Use-after-free vulnerability in the nsSMILAnimationController::DoSample function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thun…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Firefox HIGH 9.3
CVE-2012-4182

Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird …

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Firefox HIGH 9.3
CVE-2012-4183

Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunder…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Firefox HIGH 9.3
CVE-2012-4185EPSS 9%

Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunder…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10