Vulnerability index

Browse CVEs

2,886 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-23974 The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This… Firefox 86.0+ Fix from $1,6002021-02-26 HIGH 8.8 CVE-2020-26974 When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a he… Firefox 78.6.0 / 84.0+ Fix from $1,9502021-01-07 HIGH 8.8 CVE-2020-35112 If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the d… Firefox 78.6.0 / 84.0+ Fix from $1,9502021-01-07 HIGH 8.8 CVE-2020-35113 Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption an… Firefox 78.6.0 / 84.0+ Fix from $1,9502021-01-07 HIGH 8.8 CVE-2020-35114 Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 84.0+ Fix from $1,9502021-01-07 MEDIUM 6.5 CVE-2020-26975 When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, … Firefox Mobile 84.0+ Fix from $1,6002021-01-07 MEDIUM 6.5 CVE-2020-26976 When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted t… Firefox 84.0+ Fix from $1,6002021-01-07 MEDIUM 6.5 CVE-2020-26977 By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the… Firefox Mobile 84.0+ Fix from $1,6002021-01-07 MEDIUM 6.1 CVE-2020-26978 Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services r… Firefox 78.6.0 / 84.0+ Fix from $1,6002021-01-07 MEDIUM 6.1 CVE-2020-26979 When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then red… Firefox 84.0+ Fix from $1,6002021-01-07 CRITICAL 9.8 CVE-2020-26972 The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a d… Firefox 84.0+ Fix from $2,3002021-01-07 HIGH 8.8 CVE-2020-26971 Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability af… Firefox 78.6.0 / 84.0+ Fix from $1,9502021-01-07 HIGH 8.8 CVE-2020-26973 Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. Thi… Firefox 78.6.0 / 84.0+ Fix from $1,9502021-01-07 HIGH 8.8 CVE-2020-26959 During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, an… Firefox 78.5 / 83.0+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26960 If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-… Firefox 78.5 / 83.0+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26968 Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption an… Firefox 78.5 / 83.0+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26969 Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 83.0+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26970 When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depe… Thunderbird 78.5.1+ Fix from $1,9502020-12-09 MEDIUM 6.8 CVE-2020-26964 If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have conn… Firefox Mobile 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.5 CVE-2020-26957 OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some cert… Firefox Mobile 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.5 CVE-2020-26961 When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.5 CVE-2020-26965 Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.5 CVE-2020-26966 Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that s… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.5 CVE-2020-26967 When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other… Firefox 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26958 Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26962 Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used i… Firefox 83.0+ Fix from $1,6002020-12-09 HIGH 8.8 CVE-2020-26950EPSS 42% In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. Thi… Firefox 78.4.1 / 78.4.2+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26952 Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handli… Firefox 83.0+ Fix from $1,9502020-12-09 MEDIUM 6.5 CVE-2020-26955 When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on t… Firefox Mobile 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26951 A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capab… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09