Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox Mobile HIGH 9.3
CVE-2012-1127

FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…

Fix: after 10.0.3
Fix from $1,950 2012-04-25
Firefox MEDIUM 5.0
CVE-2012-0473

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thu…

Fix: after 2.9
Fix from $1,600 2012-04-25
Firefox HIGH 7.5
CVE-2012-0459

The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Th…

Fix: after 2.7
Fix from $1,950 2012-03-14
Firefox HIGH 7.5
CVE-2012-0461

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thu…

Fix: after 10.0
Fix from $1,950 2012-03-14
Firefox HIGH 7.5
CVE-2012-0462

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 throu…

Fix: after 2.7
Fix from $1,950 2012-03-14
Firefox HIGH 7.5
CVE-2012-0463

The nsWindow implementation in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird …

Fix: after 10.0
Fix from $1,950 2012-03-14
Firefox HIGH 7.5
CVE-2012-0464

Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird…

Fix: after 10.0
Fix from $1,950 2012-03-14
Firefox MEDIUM 6.8
CVE-2012-0458

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 1…

Fix: after 10.0
Fix from $1,600 2012-03-14
Firefox MEDIUM 6.4
CVE-2012-0460

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey bef…

Fix: after 2.7
Fix from $1,600 2012-03-14
Firefox HIGH 9.3
CVE-2012-0457EPSS 7%

Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, …

Fix: after 10.0
Fix from $1,950 2012-03-14
Firefox HIGH 7.5
CVE-2012-0454

Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x …

Fix: after 2.7
Fix from $1,950 2012-03-14
Firefox MEDIUM 5.0
CVE-2012-0456

The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5…

Fix: after 10.0
Fix from $1,600 2012-03-14
Bugzilla MEDIUM 5.1
CVE-2012-0453

Cross-site request forgery (CSRF) vulnerability in xmlrpc.cgi in Bugzilla 4.0.2 through 4.0.4 and 4.1.1 through 4.2rc2, when mod_perl is used, allows…

Patch available
Fix from $1,600 2012-02-25
Firefox HIGH 7.5
CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to caus…

Mitigation only
Fix from $1,950 2012-02-11
Bugzilla MEDIUM 5.1
CVE-2012-0440

Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and …

Patch available
Fix from $1,600 2012-02-02
Firefox HIGH 10.0
CVE-2012-0444EPSS 8%

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize…

Fix: 2.7 / 3.1.18+
Fix from $1,950 2012-02-01
Firefox HIGH 9.3
CVE-2012-0449EPSS 6%

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to …

Fix: 2.7 / 3.1.18+
Fix from $1,950 2012-02-01
Firefox MEDIUM 5.0
CVE-2012-0445

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation po…

Fix: after 2.7
Fix from $1,600 2012-02-01
Firefox MEDIUM 5.0
CVE-2012-0447

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon i…

Fix: after 2.7
Fix from $1,600 2012-02-01
Firefox HIGH 10.0
CVE-2012-0443

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 …

Fix: after 2.7
Fix from $1,950 2012-02-01
Firefox HIGH 9.3
CVE-2011-3659EPSS 37%

Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey befor…

Fix: 2.7 / 3.1.18+
Fix from $1,950 2012-02-01
Firefox HIGH 9.3
CVE-2012-0442

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 th…

Fix: 2.7 / 3.1.18+
Fix from $1,950 2012-02-01
Firefox MEDIUM 5.0
CVE-2011-3670

Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce th…

Fix: after 3.6.25
Fix from $1,600 2012-02-01
Bugzilla MEDIUM 6.8
CVE-2011-3667

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, …

Mitigation only
Fix from $1,600 2012-01-02
Bugzilla MEDIUM 6.8
CVE-2011-3668

Cross-site request forgery (CSRF) vulnerability in post_bug.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the aut…

No fix yet
Fix from $1,600 2012-01-02
Bugzilla MEDIUM 6.8
CVE-2011-3669

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.x before 4.2rc1 allows remote attackers to hijack the a…

No fix yet
Fix from $1,600 2012-01-02
Firefox HIGH 7.5
CVE-2011-3661

YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of…

Fix: after 2.5
Fix from $1,950 2011-12-21
Firefox HIGH 7.5
CVE-2011-3665

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (applicati…

Fix: after 2.5
Fix from $1,950 2011-12-21
Firefox MEDIUM 6.8
CVE-2011-3664

Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugin…

Fix: after 8.0
Fix from $1,600 2011-12-21
Firefox MEDIUM 6.8
CVE-2011-3666

Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted…

Fix: after 3.6.24
Fix from $1,600 2011-12-21