Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-6873 Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 121.0+ Fix from $1,9502023-12-19 MEDIUM 6.5 CVE-2023-6869 A `&lt;dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display und… Firefox 121.0+ Fix from $1,6002023-12-19 MEDIUM 6.5 CVE-2023-6872 Browser tab titles were being leaked by GNOME to system logs. This could potentially expose the browsing habits of users running in a private tab. Th… Firefox 121.0+ Fix from $1,6002023-12-19 HIGH 8.8 CVE-2023-6856EPSS 20% The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could al… Firefox 115.6 / 121.0+ Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-6858 Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.… Firefox 115.6 / 121.0+ Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-6859 A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115… Firefox 115.6 / 121.0+ Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-6861 The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox E… Firefox 115.6 / 121.0+ Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-6862 A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firef… Firefox Esr 115.6+ Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-6863 The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. Th… Firefox 115.6 / 121.0+ Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-6864 Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.6 / 121.0+ Fix from $1,9502023-12-19 HIGH 8.8 CVE-2023-6866 TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. … Firefox 121.0+ Fix from $1,9502023-12-19 MEDIUM 6.5 CVE-2023-6860 The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerab… Firefox 115.6 / 121.0+ Fix from $1,6002023-12-19 MEDIUM 6.5 CVE-2023-6865 `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk whic… Firefox 115.6 / 121.0+ Fix from $1,6002023-12-19 MEDIUM 6.1 CVE-2023-6867 The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It … Firefox 115.6 / 121.0+ Fix from $1,6002023-12-19 MEDIUM 5.3 CVE-2023-6857 When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Fire… Firefox 115.6 / 121.0+ Fix from $1,6002023-12-19 MEDIUM 6.5 CVE-2023-4421 The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctness of th… Nss 3.6.1+ Fix from $1,6002023-12-12 HIGH 8.8 CVE-2023-6212 Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.5 / 115.5.0+ Fix from $1,9502023-11-21 HIGH 8.8 CVE-2023-6213 Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 120.0+ Fix from $1,9502023-11-21 MEDIUM 6.5 CVE-2023-6210 When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from… Firefox 120.0+ Fix from $1,6002023-11-21 MEDIUM 6.5 CVE-2023-6211 If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user … Firefox 120.0+ Fix from $1,6002023-11-21 CRITICAL 9.8 CVE-2023-49060 An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulne… Firefox Mobile 120.0+ Fix from $2,3002023-11-21 HIGH 8.8 CVE-2023-6207 Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbi… Firefox 115.5 / 115.5.0+ Fix from $1,9502023-11-21 HIGH 8.8 CVE-2023-6208 When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike t… Firefox 115.5 / 115.5.0+ Fix from $1,9502023-11-21 MEDIUM 6.5 CVE-2023-6204 On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images cr… Firefox 115.5 / 115.5.0+ Fix from $1,6002023-11-21 MEDIUM 6.5 CVE-2023-6205 It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vul… Firefox 115.5 / 115.5.0+ Fix from $1,6002023-11-21 MEDIUM 6.5 CVE-2023-6209 Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specifi… Firefox 115.5 / 115.5.0+ Fix from $1,6002023-11-21 MEDIUM 6.1 CVE-2023-49061 An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS… Firefox Mobile 120.0+ Fix from $1,6002023-11-21 MEDIUM 5.4 CVE-2023-6206 The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use t… Firefox 115.5 / 115.5.0+ Fix from $1,6002023-11-21 MEDIUM 6.1 CVE-2023-5758 When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS… Firefox Mobile 119.0+ Fix from $1,6002023-10-25 CRITICAL 9.8 CVE-2023-5730 Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.4 / 115.4.1+ Fix from $2,3002023-10-25