Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2020-26965 Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.5 CVE-2020-26966 Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that s… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.5 CVE-2020-26967 When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elements other… Firefox 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26958 Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26962 Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used i… Firefox 83.0+ Fix from $1,6002020-12-09 HIGH 8.8 CVE-2020-26950EPSS 42% In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. Thi… Firefox 78.4.1 / 78.4.2+ Fix from $1,9502020-12-09 HIGH 8.8 CVE-2020-26952 Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handli… Firefox 83.0+ Fix from $1,9502020-12-09 MEDIUM 6.5 CVE-2020-26955 When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on t… Firefox Mobile 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26951 A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capab… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 6.1 CVE-2020-26956 In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affect… Firefox 78.5 / 83.0+ Fix from $1,6002020-12-09 MEDIUM 5.3 CVE-2020-6829 When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce us… Firefox 80.0+ Fix from $1,6002020-10-28 CRITICAL 9.8 CVE-2020-15683 Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence o… Firefox 78.4 / 82.0+ Fix from $2,3002020-10-22 CRITICAL 9.8 CVE-2020-15684 Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 82.0+ Fix from $2,3002020-10-22 HIGH 7.5 CVE-2020-15681 When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entr… Firefox 82.0+ Fix from $1,9502020-10-22 MEDIUM 6.5 CVE-2020-15682 When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker c… Firefox 82.0+ Fix from $1,6002020-10-22 MEDIUM 5.3 CVE-2020-15680 If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size … Firefox 82.0+ Fix from $1,6002020-10-22 HIGH 7.5 CVE-2019-17007 In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. Network Security Services 2.14.0 / 3.44+ Fix from $1,9502020-10-22 MEDIUM 6.5 CVE-2018-18508 In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a… Network Security Services 2.14.0 / 3.36.7+ Fix from $1,6002020-10-22 MEDIUM 5.9 CVE-2020-15646 If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and … Thunderbird 68.10.0+ Fix from $1,6002020-10-08 HIGH 8.8 CVE-2020-15667 When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory … Firefox 80.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15669 When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-fr… Firefox Esr 68.12+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15670 Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we pres… Firefox 78.2 / 80.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15673 Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption an… Firefox 78.3 / 81.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15674 Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 81.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15675 When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnera… Firefox 81.0+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15678 When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs be… Firefox 78.3 / 81.0+ Fix from $1,9502020-10-01 MEDIUM 6.5 CVE-2020-15664 By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object w… Firefox 68.12 / 78.2+ Fix from $1,6002020-10-01 MEDIUM 6.5 CVE-2020-15666 When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError… Firefox 80.0+ Fix from $1,6002020-10-01 MEDIUM 6.1 CVE-2020-15676 Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after past… Firefox 78.3 / 81.0+ Fix from $1,6002020-10-01 MEDIUM 6.1 CVE-2020-15677 By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the … Firefox 78.3 / 81.0+ Fix from $1,6002020-10-01