Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2020-15663 If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system… Firefox 68.12 / 78.2+ Fix from $1,9502020-10-01 HIGH 8.8 CVE-2020-15656 JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions… Firefox 78.1 / 79.0+ Fix from $1,9502020-08-10 HIGH 8.8 CVE-2020-15659 Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence o… Firefox 68.11 / 78.1.0+ Fix from $1,9502020-08-10 HIGH 7.8 CVE-2020-15657 Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placi… Firefox 78.1 / 79.0+ Fix from $1,9502020-08-10 MEDIUM 6.5 CVE-2020-15648 Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerabi… Firefox 78.0 / 78.0.2+ Fix from $1,6002020-08-10 MEDIUM 6.5 CVE-2020-15652 By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only t… Firefox 68.11 / 78.1+ Fix from $1,6002020-08-10 MEDIUM 6.5 CVE-2020-15653 An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites… Firefox 78.1 / 79.0+ Fix from $1,6002020-08-10 MEDIUM 6.5 CVE-2020-15654 When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when… Firefox 78.1 / 79.0+ Fix from $1,6002020-08-10 MEDIUM 6.5 CVE-2020-15655 A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of… Firefox 78.1 / 79.0+ Fix from $1,6002020-08-10 MEDIUM 6.5 CVE-2020-15658 The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an… Firefox 78.1 / 79.0+ Fix from $1,6002020-08-10 MEDIUM 6.5 CVE-2020-15661 A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current… Firefox Mobile 28.0+ Fix from $1,6002020-08-10 MEDIUM 6.5 CVE-2020-15662 A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintende… Firefox Mobile 28.0+ Fix from $1,6002020-08-10 MEDIUM 5.5 CVE-2020-15649 Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actua… Firefox Esr 68.11+ Fix from $1,6002020-08-10 MEDIUM 5.5 CVE-2020-15650 Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not acce… Firefox Esr 68.11+ Fix from $1,6002020-08-10 HIGH 7.4 CVE-2020-15647 A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data dis… Firefox 68.10.1+ Fix from $1,9502020-08-10 HIGH 8.8 CVE-2020-12422 In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds … Firefox 78.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12426 Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption a… Firefox 78.0+ Fix from $1,9502020-07-09 HIGH 7.8 CVE-2020-12423 When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox m… Firefox 78.0+ Fix from $1,9502020-07-09 MEDIUM 6.5 CVE-2020-12421 When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an admini… Firefox 68.10.0 / 78.0+ Fix from $1,6002020-07-09 MEDIUM 6.5 CVE-2020-12425 Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information d… Firefox 78.0+ Fix from $1,6002020-07-09 HIGH 8.8 CVE-2020-12406 Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effo… Firefox 68.9.0 / 77.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12409 When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox… Firefox 77.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12410 Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption an… Firefox 68.8.0 / 76.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12411 Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that wit… Firefox 77.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12416 A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption… Firefox 78.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12417 Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially… Firefox 68.10.0 / 78.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12419 When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free conditi… Firefox 68.10 / 68.10.0+ Fix from $1,9502020-07-09 HIGH 8.8 CVE-2020-12420 When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potenti… Firefox 68.10.0 / 78.0+ Fix from $1,9502020-07-09 MEDIUM 6.5 CVE-2020-12407 Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible scre… Firefox 77.0+ Fix from $1,6002020-07-09 MEDIUM 6.5 CVE-2020-12408 When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar.… Firefox 77.0+ Fix from $1,6002020-07-09