Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 9.3
CVE-2011-2981

The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does …

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Firefox HIGH 7.2
CVE-2011-2980

Untrusted search path vulnerability in the ThinkPadSensor::Startup function in Mozilla Firefox before 3.6.20, Thunderbird 3.x before 3.1.12, allows l…

Fix: after 3.6.19
Fix from $1,950 2011-08-18
Firefox MEDIUM 5.0
CVE-2011-2986

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used o…

Fix: after 5.0
Fix from $1,600 2011-08-18
Firefox MEDIUM 5.0
CVE-2011-2990

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other …

Mitigation only
Fix from $1,600 2011-08-18
Firefox MEDIUM 5.8
CVE-2008-7293

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to…

Fix: after 4.0
Fix from $1,600 2011-08-09
Bugzilla MEDIUM 5.0
CVE-2011-2380

Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.…

Patch available
Fix from $1,600 2011-08-09
Bugzilla MEDIUM 5.0
CVE-2011-2978

Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1…

Patch available
Fix from $1,600 2011-08-09
Bugzilla MEDIUM 5.0
CVE-2011-2979

Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows rem…

Patch available
Fix from $1,600 2011-08-09
Firefox HIGH 10.0
CVE-2011-2363EPSS 6%

Use-after-free vulnerability in the nsSVGPointList::AppendElement function in the implementation of SVG element lists in Mozilla Firefox before 3.6.1…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-2364EPSS 5%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause…

Fix: after 3.1.10
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-2365EPSS 6%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause…

Fix: after 3.1.10
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-2368

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-2371EPSS 76%

Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey thr…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-2374EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, all…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-2375EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cau…

Fix: after 4.0.1
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-2376

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and Thunderbird before 3.1.11 allow remote attackers to c…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox HIGH 7.6
CVE-2011-2373

Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when Ja…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox MEDIUM 6.4
CVE-2011-2367

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sen…

Mitigation only
Fix from $1,600 2011-06-30
Firefox MEDIUM 5.0
CVE-2011-2362

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that d…

Fix: after 3.6.17
Fix from $1,600 2011-06-30
Firefox MEDIUM 5.0
CVE-2011-2370

Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an insta…

Fix: after 4.0.1
Fix from $1,600 2011-06-30
Firefox MEDIUM 5.0
CVE-2011-2377

Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allow remote attackers to cause a denial…

Fix: after 3.6.17
Fix from $1,600 2011-06-30
Firefox HIGH 10.0
CVE-2011-0083EPSS 6%

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.1…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-0085EPSS 6%

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey throug…

Fix: after 3.6.17
Fix from $1,950 2011-06-30
Firefox HIGH 10.0
CVE-2011-0066

Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execut…

Fix: after 2.0.13
Fix from $1,950 2011-05-07
Firefox HIGH 10.0
CVE-2011-0069EPSS 7%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before…

Fix: after 3.1.9
Fix from $1,950 2011-05-07
Firefox HIGH 10.0
CVE-2011-0070EPSS 7%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1; Thunderbird before…

Fix: after 3.1.9
Fix from $1,950 2011-05-07
Firefox HIGH 10.0
CVE-2011-0072EPSS 5%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMon…

Fix: after 3.1.9
Fix from $1,950 2011-05-07
Firefox HIGH 10.0
CVE-2011-0073EPSS 70%

Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows r…

Fix: after 2.0.13
Fix from $1,950 2011-05-07
Firefox HIGH 10.0
CVE-2011-0074EPSS 5%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMon…

Fix: after 3.1.9
Fix from $1,950 2011-05-07
Firefox HIGH 10.0
CVE-2011-0075EPSS 5%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMon…

Fix: after 3.1.9
Fix from $1,950 2011-05-07