Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-17016 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could all… Firefox 68.4 / 72.0+ Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-17022 When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the … Firefox 68.4 / 72.0+ Fix from $1,6002020-01-08 MEDIUM 5.3 CVE-2019-17018 When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerabi… Firefox 72.0+ Fix from $1,6002020-01-08 MEDIUM 5.3 CVE-2019-17021 During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the pare… Firefox 68.4 / 72.0+ Fix from $1,6002020-01-08 HIGH 8.8 CVE-2019-17005 The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-si… Firefox 68.3 / 71.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-17008 When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerabili… Firefox 68.3 / 71.0+ Fix from $1,9502020-01-08 HIGH 7.8 CVE-2019-17009 When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and … Firefox 68.3 / 71.0+ Fix from $1,9502020-01-08 HIGH 7.5 CVE-2019-17010 Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a u… Firefox 68.3 / 71.0+ Fix from $1,9502020-01-08 HIGH 7.5 CVE-2019-17011 Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free conditio… Firefox 68.3 / 71.0+ Fix from $1,9502020-01-08 MEDIUM 6.1 CVE-2019-17001 A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-si… Firefox Mitigation only Fix from $1,6002020-01-08 HIGH 8.8 CVE-2019-11764 Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence o… Firefox 68.2 / 70.0+ Fix from $1,9502020-01-08 MEDIUM 6.5 CVE-2019-11765 A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However,… Firefox 70.0+ Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-17000 An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if … Firefox 70.0+ Fix from $1,6002020-01-08 HIGH 8.8 CVE-2019-11745 When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could… Firefox 2.14.0 / 68.3+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11756 Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability… Firefox 71.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11757 When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulte… Firefox 68.2 / 70.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11758 Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence o… Firefox 68.2 / 69.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11759 An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to… Firefox 68.2 / 70.0+ Fix from $1,9502020-01-08 HIGH 8.8 CVE-2019-11760 A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances.… Firefox 68.2 / 70.0+ Fix from $1,9502020-01-08 MEDIUM 6.1 CVE-2019-11762 If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/s… Firefox 68.2 / 70.0+ Fix from $1,6002020-01-08 MEDIUM 6.1 CVE-2019-11763 Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to H… Firefox 68.2 / 70.0+ Fix from $1,6002020-01-08 MEDIUM 5.4 CVE-2019-11761 By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from expos… Firefox 68.2 / 70.0+ Fix from $1,6002020-01-08 MEDIUM 6.5 CVE-2013-1689 Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames. Firefox after 19.0.2 Fix from $1,6002019-12-10 HIGH 7.5 CVE-2019-11755 A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, althoug… Thunderbird 68.1.1+ Fix from $1,9502019-09-27 HIGH 8.8 CVE-2019-11751 Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicio… Firefox 68.1.0 / 69.0+ Fix from $1,9502019-09-27 HIGH 8.8 CVE-2019-11752 It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentia… Firefox 60.9.0 / 68.1.0+ Fix from $1,9502019-09-27 HIGH 7.8 CVE-2019-11753 The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged use… Firefox 60.9.0 / 68.1.0+ Fix from $1,9502019-09-27 MEDIUM 6.5 CVE-2019-11750 A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox … Firefox 68.1.0 / 69.0+ Fix from $1,6002019-09-27 HIGH 8.8 CVE-2019-11746 A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exp… Firefox 60.9.0 / 68.1.0+ Fix from $1,9502019-09-27 MEDIUM 6.5 CVE-2019-11747 The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This inc… Firefox 68.1.0 / 69.0+ Fix from $1,6002019-09-27