Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2024-4765 Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. T… Firefox 126.0+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-4764 Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126. Firefox 126.0+ Fix from $2,3002024-05-14 HIGH 8.8 CVE-2024-4367EPSS 73% A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability af… Firefox 7.10.6 / 115.11.0+ Fix from $1,9502024-05-14 CRITICAL 9.8 CVE-2024-3863 The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other oper… Firefox 115.10 / 115.10.0+ Fix from $2,3002024-04-16 HIGH 8.8 CVE-2024-3854 In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox… Firefox 115.10 / 125.0+ Fix from $1,9502024-04-16 HIGH 8.8 CVE-2024-3856 A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 12… Firefox 125.0+ Fix from $1,9502024-04-16 HIGH 8.1 CVE-2024-3864 Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that… Firefox 115.10.0 / 125.0+ Fix from $1,9502024-04-16 HIGH 8.1 CVE-2024-3865 Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 125.0+ Fix from $1,9502024-04-16 HIGH 7.8 CVE-2024-3857 The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerabi… Firefox 115.10 / 125.0+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-3852 GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR <… Firefox 115.10 / 125.0+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-3853 A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability aff… Firefox 125.0+ Fix from $1,9502024-04-16 HIGH 7.5 CVE-2024-3858 It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125. Firefox 125.0+ Fix from $1,9502024-04-16 MEDIUM 6.5 CVE-2024-3855 In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125. Firefox 125.0+ Fix from $1,6002024-04-16 MEDIUM 6.2 CVE-2024-3860 An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash… Firefox 125.0+ Fix from $1,6002024-04-16 MEDIUM 5.9 CVE-2024-3859 On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. T… Firefox 115.10 / 125.0+ Fix from $1,6002024-04-16 MEDIUM 5.3 CVE-2024-3862 The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulner… Firefox 125.0+ Fix from $1,6002024-04-16 HIGH 7.5 CVE-2024-31392 If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnera… Firefox 124.0+ Fix from $1,9502024-04-03 CRITICAL 9.8 CVE-2024-29943EPSS 23% An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds check elimination. This vulnerabi… Firefox 124.0.1+ Fix from $2,3002024-03-22 HIGH 8.4 CVE-2024-29944 An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note:… Firefox 115.9.1+ Fix from $1,9502024-03-22 CRITICAL 9.8 CVE-2024-2615 Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 124.0+ Fix from $2,3002024-03-19 HIGH 8.8 CVE-2024-2614 Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.8.0 / 123.0+ Fix from $1,9502024-03-19 HIGH 8.1 CVE-2024-2612 If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to ach… Firefox 115.9 / 124.0+ Fix from $1,9502024-03-19 HIGH 7.5 CVE-2024-2613 Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerabilit… Firefox 124.0+ Fix from $1,9502024-03-19 MEDIUM 5.5 CVE-2024-2611 A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affec… Firefox 115.9.0 / 124.0+ Fix from $1,6002024-03-19 HIGH 8.4 CVE-2024-2608 `AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing … Firefox 115.9.0 / 124.0+ Fix from $1,9502024-03-19 HIGH 8.1 CVE-2024-2607 Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. O… Firefox 115.9.0 / 124.0+ Fix from $1,9502024-03-19 MEDIUM 6.1 CVE-2024-2609 The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This… Firefox 115.10.0 / 124.0+ Fix from $1,6002024-03-19 MEDIUM 6.1 CVE-2024-2610 Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulne… Firefox 115.9.0 / 124.0+ Fix from $1,6002024-03-19 MEDIUM 5.9 CVE-2024-2605 An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affecte… Firefox 115.9.0 / 124.0+ Fix from $1,6002024-03-19 MEDIUM 6.5 CVE-2023-5388 NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the pr… Firefox 115.9.0 / 124.0+ Fix from $1,6002024-03-19