Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 9.3
CVE-2010-3131EPSS 22%

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and Sea…

Fix: after 3.5.11
Fix from $1,950 2010-08-26
Bugzilla MEDIUM 6.5
CVE-2010-2757

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonat…

Mitigation only
Fix from $1,600 2010-08-16
Bugzilla MEDIUM 5.0
CVE-2010-2756

Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the …

Mitigation only
Fix from $1,600 2010-08-16
Bugzilla MEDIUM 5.0
CVE-2010-2758

Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whethe…

Mitigation only
Fix from $1,600 2010-08-16
Firefox HIGH 9.3
CVE-2010-2752EPSS 10%

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Firefox HIGH 8.8
CVE-2010-2753EPSS 7%

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey …

Fix: 2.0.6 / 3.0.6+
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-1209EPSS 5%

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-1211

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-1212

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a…

Mitigation only
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-1214EPSS 8%

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitr…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Firefox HIGH 8.8
CVE-2010-1208EPSS 5%

Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before…

Fix: 2.0.6 / 3.5.11+
Fix from $1,950 2010-07-30
Firefox MEDIUM 6.8
CVE-2010-1215

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrap…

Mitigation only
Fix from $1,600 2010-07-30
Firefox HIGH 10.0
CVE-2010-2755

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows rem…

Mitigation only
Fix from $1,950 2010-07-30
Firefox MEDIUM 5.0
CVE-2010-2754

dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, an…

Fix: after 2.0.5
Fix from $1,600 2010-07-30
Bugzilla MEDIUM 5.0
CVE-2010-1204

Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive t…

Mitigation only
Fix from $1,600 2010-06-28
Firefox HIGH 9.3
CVE-2010-0183

Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows rem…

Fix: after 2.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1196

Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird bef…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1198

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to ex…

Fix: after 2.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1199EPSS 11%

Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1200EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, a…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1201EPSS 6%

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows r…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1202

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1203

The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application cr…

Mitigation only
Fix from $1,950 2010-06-24
Firefox HIGH 10.0
CVE-2010-1988EPSS 6%

Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or poss…

No fix yet
Fix from $1,950 2010-05-20
Firefox MEDIUM 5.0
CVE-2010-1986

Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScrip…

No fix yet
Fix from $1,600 2010-05-20
Firefox MEDIUM 5.0
CVE-2010-1987

Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application…

No fix yet
Fix from $1,600 2010-05-20
Firefox MEDIUM 5.0
CVE-2010-1990

Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL…

Fix: after 3.0.19
Fix from $1,600 2010-05-20
Firefox HIGH 9.3
CVE-2010-1585

The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before…

Fix: after 3.1.7
Fix from $1,950 2010-04-28
Firefox HIGH 10.0
CVE-2010-0174EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird …

Fix: after 3.5.7
Fix from $1,950 2010-04-05
Firefox HIGH 9.3
CVE-2010-0173

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaM…

Fix: after 3.5.7
Fix from $1,950 2010-04-05