Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2019-11748 WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. I… Firefox 68.1.0 / 69.0+ Fix from $1,6002019-09-27 MEDIUM 6.1 CVE-2019-11744 Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to… Firefox 60.9 / 68.1+ Fix from $1,6002019-09-27 CRITICAL 9.8 CVE-2019-11733 When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found … Firefox 68.0.2+ Fix from $2,3002019-09-27 CRITICAL 9.8 CVE-2019-11734 Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption a… Firefox 69.0+ Fix from $2,3002019-09-27 HIGH 8.8 CVE-2019-11735 Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of … Firefox 68.1.0 / 69.0+ Fix from $1,9502019-09-27 HIGH 8.8 CVE-2019-11740 Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs show… Firefox 60.9.0 / 68.1.0+ Fix from $1,9502019-09-27 HIGH 7.0 CVE-2019-11736 The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement … Firefox 68.1.0 / 69.0+ Fix from $1,9502019-09-27 MEDIUM 6.5 CVE-2019-11739 Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affe… Thunderbird 60.9.0 / 68.1.0+ Fix from $1,6002019-09-27 MEDIUM 6.5 CVE-2019-11742 A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due… Firefox 60.9.0 / 68.1.0+ Fix from $1,6002019-09-27 MEDIUM 6.3 CVE-2019-11738 If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascri… Firefox 68.1.0 / 69.0+ Fix from $1,6002019-09-27 MEDIUM 6.1 CVE-2019-11741 A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to be loaded… Firefox 69.0+ Fix from $1,6002019-09-27 MEDIUM 5.3 CVE-2019-11737 If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive will be igno… Firefox 69.0+ Fix from $1,6002019-09-27 CRITICAL 9.8 CVE-2019-9819 A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. Thi… Firefox 60.7 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-9820 A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable c… Firefox 60.7 / 60.7.0+ Fix from $2,3002019-07-23 HIGH 8.3 CVE-2019-9818 A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in t… Firefox 60.7 / 67.0+ Fix from $1,9502019-07-23 HIGH 8.1 CVE-2019-9815 If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an… Firefox 60.7 / 67.0+ Fix from $1,9502019-07-23 HIGH 8.1 CVE-2019-9821 A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable… Firefox 67.0+ Fix from $1,9502019-07-23 MEDIUM 5.9 CVE-2019-9816EPSS 6% A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of s… Firefox 60.7 / 67.0+ Fix from $1,6002019-07-23 MEDIUM 5.3 CVE-2019-9817 Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site … Firefox 60.7 / 67.0+ Fix from $1,6002019-07-23 CRITICAL 9.8 CVE-2019-9800 Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bug… Firefox 60.7 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-9814 Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption a… Firefox 67.0+ Fix from $2,3002019-07-23 HIGH 8.3 CVE-2019-9811 As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser fea… Firefox 60.8 / 68.0+ Fix from $1,9502019-07-23 HIGH 7.5 CVE-2019-11719 When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Secur… Firefox 60.8.0 / 68.0+ Fix from $1,9502019-07-23 HIGH 7.5 CVE-2019-11723 A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could l… Firefox 68.0+ Fix from $1,9502019-07-23 HIGH 7.5 CVE-2019-11729 Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and u… Firefox 60.8.0 / 68.0+ Fix from $1,9502019-07-23 MEDIUM 6.5 CVE-2019-11721 The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not … Firefox 68.0+ Fix from $1,6002019-07-23 MEDIUM 6.5 CVE-2019-11725 When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources fr… Firefox 68.0+ Fix from $1,6002019-07-23 MEDIUM 6.5 CVE-2019-11730EPSS 20% A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or s… Firefox 60.8 / 68.0+ Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2019-11720 Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows mal… Firefox 68.0+ Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2019-11724 Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to … Firefox 68.0+ Fix from $1,6002019-07-23