Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2007-5967 A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval. Firefox Mitigation only Fix from $1,6002021-05-17 HIGH 8.8 CVE-2021-23987 Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence o… Firefox 78.9 / 87.0+ Fix from $1,9502021-03-31 HIGH 8.8 CVE-2021-23988 Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 87.0+ Fix from $1,9502021-03-31 MEDIUM 6.5 CVE-2021-23982 Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services r… Firefox 78.9 / 87.0+ Fix from $1,6002021-03-31 MEDIUM 6.5 CVE-2021-23983 By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corrup… Firefox 87.0+ Fix from $1,6002021-03-31 MEDIUM 6.5 CVE-2021-23984 A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully cont… Firefox 78.9 / 87.0+ Fix from $1,6002021-03-31 MEDIUM 6.5 CVE-2021-23985 If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feat… Firefox 87.0+ Fix from $1,6002021-03-31 MEDIUM 6.5 CVE-2021-23986 A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response… Firefox 87.0+ Fix from $1,6002021-03-31 HIGH 8.1 CVE-2021-23981 A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corrup… Firefox 78.9 / 87.0+ Fix from $1,9502021-03-31 MEDIUM 6.1 CVE-2021-21354 Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things during the Firefox release p… Pollbot 1.4.4+ Fix from $1,6002021-03-08 HIGH 8.8 CVE-2021-23964 Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption an… Firefox 78.7 / 85.0+ Fix from $1,9502021-02-26 HIGH 8.8 CVE-2021-23965 Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 85.0+ Fix from $1,9502021-02-26 HIGH 8.8 CVE-2021-23978 Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption an… Firefox 78.8 / 86.0+ Fix from $1,9502021-02-26 HIGH 8.8 CVE-2021-23979 Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 86.0+ Fix from $1,9502021-02-26 HIGH 8.8 CVE-2021-23962 Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects… Firefox 85.0+ Fix from $1,9502021-02-26 MEDIUM 5.3 CVE-2021-23977 Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from applicat… Firefox 86.0+ Fix from $1,6002021-02-26 HIGH 8.8 CVE-2021-23954 Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a … Firefox 78.7 / 85.0+ Fix from $1,9502021-02-26 HIGH 8.8 CVE-2021-23960 Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerab… Firefox 78.7 / 85.0+ Fix from $1,9502021-02-26 HIGH 7.4 CVE-2021-23957 Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox… Firefox 85.0+ Fix from $1,9502021-02-26 HIGH 7.4 CVE-2021-23961 Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as wel… Firefox 85.0+ Fix from $1,9502021-02-26 MEDIUM 6.5 CVE-2021-23956 An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was … Firefox 85.0+ Fix from $1,6002021-02-26 MEDIUM 6.5 CVE-2021-23958 The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnera… Firefox 85.0+ Fix from $1,6002021-02-26 MEDIUM 6.1 CVE-2021-23955 The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vul… Firefox 85.0+ Fix from $1,6002021-02-26 MEDIUM 6.1 CVE-2021-23959 An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only… Firefox 85.0+ Fix from $1,6002021-02-26 HIGH 8.8 CVE-2021-23972 One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]'. To mitigate this type of a… Firefox 86.0+ Fix from $1,9502021-02-26 HIGH 8.1 CVE-2021-23976 When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring w… Firefox 86.0+ Fix from $1,9502021-02-26 MEDIUM 6.5 CVE-2021-23970 Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability aff… Firefox 86.0+ Fix from $1,6002021-02-26 MEDIUM 6.5 CVE-2021-23971 When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially… Firefox 86.0+ Fix from $1,6002021-02-26 MEDIUM 6.5 CVE-2021-23973 When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have reve… Firefox 78.8 / 86.0+ Fix from $1,6002021-02-26 MEDIUM 6.5 CVE-2021-23975 The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function … Firefox 86.0+ Fix from $1,6002021-02-26