Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-25751 Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a po… Firefox 102.9 / 111.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-25752 When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead f… Firefox 102.9 / 111.0+ Fix from $1,6002023-06-02 MEDIUM 5.4 CVE-2023-25730 A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinite… Firefox 102.8 / 110.0+ Fix from $1,6002023-06-02 HIGH 8.8 CVE-2023-0767 An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mi… Firefox 102.8 / 110.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-23605 Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed e… Firefox 102.7 / 109.0+ Fix from $1,9502023-06-02 HIGH 8.8 CVE-2023-23606 Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs showed evidence of memory corr… Firefox 109.0+ Fix from $1,9502023-06-02 MEDIUM 6.5 CVE-2023-0430 Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as hav… Thunderbird 102.7.1+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-0547 OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thu… Thunderbird 102.10+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-0616 If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which cou… Thunderbird 102.8+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-1945 Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affec… Firefox Esr 102.10+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23597 A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` co… Firefox 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23598 Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a w… Firefox 102.7 / 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23599 When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary… Firefox 102.7 / 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23600 Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. Thi… Firefox 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23601 Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vul… Firefox 102.7 / 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23602 A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could … Firefox 102.7 / 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23603 Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for externa… Firefox 102.7 / 109.0+ Fix from $1,6002023-06-02 MEDIUM 6.5 CVE-2023-23604 A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have l… Firefox 109.0+ Fix from $1,6002023-06-02 CRITICAL 9.8 CVE-2021-43529 Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird ver… Thunderbird 91.3.0+ Fix from $2,3002023-02-16 HIGH 7.5 CVE-2020-6817 bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed … Bleach 3.1.4+ Fix from $1,9502023-02-16 MEDIUM 6.1 CVE-2019-17003 Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed. Firefox Mobile after 25.0 Fix from $1,6002023-02-16 MEDIUM 6.1 CVE-2021-23980 A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script… Bleach 3.3.0+ Fix from $1,6002023-02-16 MEDIUM 6.1 CVE-2022-0637 open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6 Pollbot 1.4.6+ Fix from $1,6002023-02-16 MEDIUM 5.9 CVE-2020-12413 The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support … Firefox 68.10.0 / 78.0+ Fix from $1,6002023-02-16 HIGH 8.8 CVE-2022-46885 Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs s… Firefox 106.0+ Fix from $1,9502022-12-22 CRITICAL 9.8 CVE-2022-46882 A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6… Firefox 102.6 / 107.0+ Fix from $2,3002022-12-22 HIGH 8.8 CVE-2022-46879 Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safety bugs pre… Firefox 108.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-46881 An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advis… Firefox 102.6 / 106.0+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-46883 Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106.… Firefox 107.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-46880 A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on De… Firefox 102.6 / 105.0+ Fix from $1,6002022-12-22