Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2021-29969 If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the S… Thunderbird 78.12+ Fix from $1,6002021-08-05 MEDIUM 6.1 CVE-2021-29979 Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s prim… Hubs Cloud Mitigation only Fix from $1,6002021-08-02 HIGH 8.8 CVE-2020-15660 Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically p… Geckodriver 0.27.0+ Fix from $1,9502021-07-20 CRITICAL 9.8 CVE-2021-29954 Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service. This vulnerability af… Hubs Cloud Reticulum 1.0.1+ Fix from $2,3002021-06-24 HIGH 8.8 CVE-2021-29966 Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 89.0+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-29967 Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption a… Firefox 78.11 / 89.0+ Fix from $1,9502021-06-24 HIGH 8.1 CVE-2021-29968 When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operatin… Firefox 89.0.1+ Fix from $1,9502021-06-24 HIGH 7.1 CVE-2021-29964 A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This… Firefox 78.11 / 89.0+ Fix from $1,9502021-06-24 MEDIUM 6.1 CVE-2021-29953 A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resu… Firefox 88.0.1 / 88.1.3+ Fix from $1,6002021-06-24 MEDIUM 5.3 CVE-2021-29955 A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have … Firefox 78.9 / 87.0+ Fix from $1,6002021-06-24 MEDIUM 5.3 CVE-2021-29965 A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords for the cu… Firefox 89.0+ Fix from $1,6002021-06-24 HIGH 8.8 CVE-2021-23994 A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ES… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-23995 When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-23997 Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enough effor… Firefox 88.0+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-23999 If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges t… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-24002 When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed a… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-29946 Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the A… Firefox 78.10 / 88.0+ Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-29947 Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption a… Firefox 88.0+ Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-29949 When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that is… Thunderbird 78.9.1+ Fix from $1,9502021-06-24 HIGH 7.5 CVE-2021-29950 Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secr… Thunderbird 78.8.1+ Fix from $1,9502021-06-24 HIGH 7.5 CVE-2021-29952 When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have be… Firefox 88.0.1 / 88.1.3+ Fix from $1,9502021-06-24 MEDIUM 6.8 CVE-2021-23991 If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has… Thunderbird 78.9.1+ Fix from $1,6002021-06-24 MEDIUM 6.5 CVE-2021-23993 An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key … Thunderbird 78.9.1+ Fix from $1,6002021-06-24 MEDIUM 6.5 CVE-2021-23996 By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofing attack t… Firefox 88.0+ Fix from $1,6002021-06-24 MEDIUM 6.5 CVE-2021-23998 Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects… Firefox 78.10 / 88.0+ Fix from $1,6002021-06-24 MEDIUM 6.5 CVE-2021-29945 The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affec… Firefox 78.10 / 88.0+ Fix from $1,6002021-06-24 MEDIUM 6.5 CVE-2021-29951 The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start … Firefox 78.10.1 / 87.0+ Fix from $1,6002021-06-24 MEDIUM 6.1 CVE-2021-29944 Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTM… Firefox 88.0+ Fix from $1,6002021-06-24 MEDIUM 6.1 CVE-2011-3656 Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or… Firefox 3.6.24+ Fix from $1,6002021-06-02 CRITICAL 9.1 CVE-2020-12403 A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-b… Nss 3.55+ Fix from $2,3002021-05-27