Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2024-1563 An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox sc… Firefox Focus 122.0+ Fix from $1,9502024-02-22 HIGH 7.8 CVE-2024-26283 An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox sc… Firefox 123.0+ Fix from $1,9502024-02-22 HIGH 7.1 CVE-2024-26282 Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Fire… Firefox 123.0+ Fix from $1,9502024-02-22 MEDIUM 6.1 CVE-2024-26284 Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to t… Firefox Focus 123.0+ Fix from $1,6002024-02-22 HIGH 8.3 CVE-2024-1555 When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 12… Firefox 123.0+ Fix from $1,9502024-02-20 HIGH 8.1 CVE-2024-1557 Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 123.0+ Fix from $1,9502024-02-20 MEDIUM 6.5 CVE-2024-1556 The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This… Firefox 123.0+ Fix from $1,6002024-02-20 CRITICAL 9.8 CVE-2024-1554 The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Und… Firefox 123.0+ Fix from $2,3002024-02-20 HIGH 8.1 CVE-2024-1553 Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.8.0 / 123.0+ Fix from $1,9502024-02-20 HIGH 7.5 CVE-2024-1546 When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. … Firefox 115.8.0 / 123.0+ Fix from $1,9502024-02-20 HIGH 7.5 CVE-2024-1552 Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit AR… Firefox 115.8.0 / 123.0+ Fix from $1,9502024-02-20 MEDIUM 6.5 CVE-2024-1547 Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim websit… Firefox 115.8.0 / 123.0+ Fix from $1,6002024-02-20 MEDIUM 6.1 CVE-2024-1549 If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confus… Firefox 115.8.0 / 123.0+ Fix from $1,6002024-02-20 MEDIUM 6.1 CVE-2024-1550 A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned u… Firefox 115.8.0 / 123.0+ Fix from $1,6002024-02-20 MEDIUM 6.1 CVE-2024-1551 Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header… Firefox 115.8.0 / 123.0+ Fix from $1,6002024-02-20 MEDIUM 6.1 CVE-2024-0953 When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi… Firefox Mobile No fix yet Fix from $1,6002024-02-05 HIGH 8.8 CVE-2024-0745 The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnera… Firefox 122.0+ Fix from $1,9502024-01-23 HIGH 8.8 CVE-2024-0750 A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerabil… Firefox 115.7 / 122.0+ Fix from $1,9502024-01-23 HIGH 8.8 CVE-2024-0751 A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde… Firefox 115.7 / 122.0+ Fix from $1,9502024-01-23 HIGH 8.8 CVE-2024-0755 Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.7 / 122.0+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-0743 An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox … Firefox 122.0+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2024-0744 In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerabilit… Firefox 122.0+ Fix from $1,9502024-01-23 MEDIUM 6.5 CVE-2024-0741 An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affec… Firefox 115.7 / 122.0+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-0746 A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, … Firefox 115.7 / 122.0+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-0747 When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Secur… Firefox 115.7 / 122.0+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-0752 A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an expl… Firefox 122.0+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-0753 In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, a… Firefox 115.7 / 122.0+ Fix from $1,6002024-01-23 MEDIUM 6.5 CVE-2024-0754 Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122. Firefox 122.0+ Fix from $1,6002024-01-23 HIGH 7.5 CVE-2024-0605 Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses s… Firefox Focus 122.0+ Fix from $1,9502024-01-22 MEDIUM 6.1 CVE-2024-0606 An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthoriz… Firefox Focus 122.0+ Fix from $1,6002024-01-22