Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-6607 It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `&lt;select&gt;` e… Firefox 128.0+ Fix from $1,9502024-07-09 HIGH 8.8 CVE-2024-6609 When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and T… Firefox 128.0+ Fix from $1,9502024-07-09 HIGH 8.2 CVE-2024-6606 Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 a… Firefox 128.0+ Fix from $1,9502024-07-09 HIGH 7.5 CVE-2024-6604 Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we… Firefox 115.13 / 126.0+ Fix from $1,9502024-07-09 HIGH 7.4 CVE-2024-6603 In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vu… Firefox 115.13 / 128.0+ Fix from $1,9502024-07-09 MEDIUM 6.3 CVE-2024-6600 Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in… Firefox 115.13 / 128.0+ Fix from $1,6002024-07-09 MEDIUM 6.5 CVE-2024-38312 When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundl… Firefox Mobile 127.0+ Fix from $1,6002024-06-13 CRITICAL 9.8 CVE-2024-5695 If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered,… Firefox 127.0+ Fix from $2,3002024-06-11 CRITICAL 9.8 CVE-2024-5699 In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked w… Firefox 127.0+ Fix from $2,3002024-06-11 CRITICAL 9.8 CVE-2024-5701 Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 127.0+ Fix from $2,3002024-06-11 HIGH 8.6 CVE-2024-5696 By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vul… Firefox 115.12 / 127.0+ Fix from $1,9502024-06-11 HIGH 7.5 CVE-2024-5702 Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < … Firefox 115.12 / 125.0+ Fix from $1,9502024-06-11 HIGH 7.0 CVE-2024-5700 Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we… Firefox 115.12 / 127.0+ Fix from $1,9502024-06-11 MEDIUM 6.1 CVE-2024-5698 By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have le… Firefox 127+ Fix from $1,6002024-06-11 HIGH 8.1 CVE-2024-5688 If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Fi… Firefox 115.12 / 127.0+ Fix from $1,9502024-06-11 HIGH 7.5 CVE-2024-5694 An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerabili… Firefox 127.0+ Fix from $1,9502024-06-11 MEDIUM 6.5 CVE-2024-5692 On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension su… Firefox 115.12 / 127.0+ Fix from $1,6002024-06-11 MEDIUM 6.1 CVE-2024-5693 Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin… Firefox 115.12 / 127.0+ Fix from $1,6002024-06-11 MEDIUM 5.3 CVE-2024-5687 If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been incorrect. … Firefox 127.0+ Fix from $1,6002024-06-11 CRITICAL 9.8 CVE-2024-4778 Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 126.0+ Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-4777 Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we… Firefox 115.11.0 / 126.0+ Fix from $1,9502024-05-14 HIGH 8.2 CVE-2024-4776 A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126. Firefox 126.0+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-4773 When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfu… Firefox 126.0+ Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2024-4774 The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. Thi… Firefox 126.0+ Fix from $1,6002024-05-14 MEDIUM 5.9 CVE-2024-4772 An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 1… Firefox 126.0+ Fix from $1,6002024-05-14 MEDIUM 5.9 CVE-2024-4775 An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined b… Firefox 126.0+ Fix from $1,6002024-05-14 HIGH 8.8 CVE-2024-4770 When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox … Firefox 115.11.0 / 126.0+ Fix from $1,9502024-05-14 HIGH 8.6 CVE-2024-4771 A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially… Firefox 126.0+ Fix from $1,9502024-05-14 MEDIUM 6.1 CVE-2024-4768 A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability … Firefox 115.11.0 / 126.0+ Fix from $1,6002024-05-14 MEDIUM 5.9 CVE-2024-4769 When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script… Firefox 115.11.0 / 126.0+ Fix from $1,6002024-05-14