Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.7 CVE-2025-0241 When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability was fixed in… Firefox 128.6.0 / 134.0+ Fix from $1,9502025-01-07 MEDIUM 6.5 CVE-2025-0242EPSS 13% Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of… Firefox 128.6.0 / 134.0+ Fix from $1,6002025-01-07 MEDIUM 5.4 CVE-2025-0237 The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the prin… Firefox 128.6.0 / 134.0+ Fix from $1,6002025-01-07 MEDIUM 5.3 CVE-2025-0238 Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vuln… Firefox 115.19.0 / 128.6+ Fix from $1,6002025-01-07 MEDIUM 5.1 CVE-2025-0243 Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory co… Firefox 128.6.0 / 133.0+ Fix from $1,6002025-01-07 MEDIUM 5.4 CVE-2024-53975 Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure… Firefox 133.0+ Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-53976 Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL wa… Firefox 133.0+ Fix from $1,6002024-11-26 MEDIUM 6.5 CVE-2024-11706 A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling m… Firefox 133.0+ Fix from $1,6002024-11-26 MEDIUM 6.5 CVE-2024-11708 Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefo… Firefox 133.0+ Fix from $1,6002024-11-26 CRITICAL 9.8 CVE-2024-11698 A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was op… Firefox 128.5.0 / 133.0+ Fix from $2,3002024-11-26 CRITICAL 9.8 CVE-2024-11704 A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symme… Firefox 128.7.0 / 133.0+ Fix from $2,3002024-11-26 CRITICAL 9.1 CVE-2024-11705 `NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred… Firefox 133.0+ Fix from $2,3002024-11-26 HIGH 8.8 CVE-2024-11697 When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This co… Firefox 128.5.0 / 133.0+ Fix from $1,9502024-11-26 HIGH 8.8 CVE-2024-11699 Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we p… Firefox 128.5 / 128.5.0+ Fix from $1,9502024-11-26 HIGH 8.1 CVE-2024-11700 Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the … Firefox 133.0+ Fix from $1,9502024-11-26 HIGH 7.5 CVE-2024-11702 Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboa… Firefox 133.0+ Fix from $1,9502024-11-26 MEDIUM 5.7 CVE-2024-11703 On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects… Firefox 133.0+ Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-11695 A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing att… Firefox 128.5.0 / 133.0+ Fix from $1,6002024-11-26 MEDIUM 5.4 CVE-2024-11696 The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, trigger… Firefox 128.5.0 / 133.0+ Fix from $1,6002024-11-26 CRITICAL 9.8 CVE-2024-11693 The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other … Firefox 128.5.0 / 133.0+ Fix from $2,3002024-11-26 HIGH 8.8 CVE-2024-11691 Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's G… Firefox 115.18.0 / 128.5.0+ Fix from $1,9502024-11-26 MEDIUM 6.1 CVE-2024-11694 Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shi… Firefox 115.8.0 / 115.18.0+ Fix from $1,6002024-11-26 HIGH 7.8 CVE-2023-1521 On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library pass… Sccache 0.4.0+ Fix from $1,9502024-11-26 MEDIUM 6.1 CVE-2023-2142 In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If ther… Nunjucks 3.2.4+ Fix from $1,6002024-11-26 HIGH 8.4 CVE-2023-0163 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker … Convict 6.2.4+ Fix from $1,9502024-11-26 MEDIUM 6.5 CVE-2024-10941 A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Fire… Firefox 126.0+ Fix from $1,6002024-11-06 HIGH 8.8 CVE-2024-10467 Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we p… Firefox 128.4.0 / 132.0+ Fix from $1,9502024-10-29 HIGH 7.5 CVE-2024-10466 By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vul… Firefox 128.4.0 / 132.0+ Fix from $1,9502024-10-29 MEDIUM 6.5 CVE-2024-10463 Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < … Firefox 115.17.0 / 128.4.0+ Fix from $1,6002024-10-29 MEDIUM 6.5 CVE-2024-10464 Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by int… Firefox 128.4.0 / 132.0+ Fix from $1,6002024-10-29