Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-29539 When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. T… Firefox 102.10 / 112.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-29541 Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br… Firefox 102.10 / 112.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-29543 An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This … Firefox 112.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-29550 Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with eno… Firefox 102.10 / 112.0+ Fix from $1,9502023-06-02 HIGH 7.5 CVE-2023-29537 Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability… Firefox 112.0+ Fix from $1,9502023-06-02 MEDIUM 6.5 CVE-2023-28160 When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially… Firefox 111.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-28163 When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resol… Firefox 102.9 / 111.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-28164 Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulner… Firefox 102.9 / 111.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-29535 Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and … Firefox 102.10 / 112.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-29544 If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentia… Firefox 112.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-29547 When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently f… Firefox 102.10 / 112.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-29548 A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for A… Firefox 102.10 / 112.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-29549 Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability… Firefox 112.0+ Fix from $1,6002023-06-02 MEDIUM 6.1 CVE-2023-29540 Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <cod… Firefox 112.0+ Fix from $1,6002023-06-02 HIGH 8.8 CVE-2023-25729 Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them wi… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25731 Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global o… Firefox 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25732 When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentiall… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25735 Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25737 An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25739 Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext<… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25740 After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected … Firefox 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25744 Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with en… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25745 Memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-25746 Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some … Firefox Esr 102.8+ Fix from $1,9502023-06-02 HIGH 8.1 CVE-2023-25734 After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpecte… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 7.5 CVE-2023-25743 A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects … Firefox Focus Mitigation only Fix from $1,9502023-06-02 MEDIUM 6.5 CVE-2023-25728 The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with tha… Firefox 102.8 / 110.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-25738 Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which … Firefox 102.8 / 110.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-25741 When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compa… Firefox 110.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-25742 When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefo… Firefox 102.8 / 110.0+ Fix from $1,6002023-06-02