Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2019-11727 A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those ar… Firefox 68.0+ Fix from $1,6002019-07-23 CRITICAL 10.0 CVE-2019-11708 KEVEPSS 56% Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent … Firefox 60.7.2 / 67.0.4+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11704EPSS 11% A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages,… Thunderbird 60.7.1+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11705EPSS 10% A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, res… Thunderbird 60.7.1+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11709 Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence o… Firefox 60.8.0 / 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11710 Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption a… Firefox 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11713 A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable c… Firefox 60.8.0 / 68.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11714 Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerabili… Firefox 68.0+ Fix from $2,3002019-07-23 HIGH 8.8 CVE-2019-11707 KEVEPSS 38% A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We… Firefox 60.7.1 / 60.7.2+ Fix from $1,9502019-07-23 HIGH 8.8 CVE-2019-11711 When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever c… Firefox 60.8.0 / 68.0+ Fix from $1,9502019-07-23 HIGH 8.8 CVE-2019-11712 POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attac… Firefox 60.8.0 / 68.0+ Fix from $1,9502019-07-23 HIGH 8.3 CVE-2019-11716 Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(… Firefox 68.0+ Fix from $1,9502019-07-23 HIGH 7.5 CVE-2019-11706EPSS 10% A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email message… Thunderbird 60.7.1+ Fix from $1,9502019-07-23 MEDIUM 6.1 CVE-2019-11715 Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web site… Firefox 60.8.0 / 68.0+ Fix from $1,6002019-07-23 MEDIUM 5.3 CVE-2019-11717 A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for… Firefox 60.8.0 / 68.0+ Fix from $1,6002019-07-23 MEDIUM 5.3 CVE-2019-11718 Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page with… Firefox 68.0+ Fix from $1,6002019-07-23 CRITICAL 9.8 CVE-2019-11693 The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content f… Firefox 60.7.0 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11703EPSS 11% A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resultin… Thunderbird 60.7.1+ Fix from $2,3002019-07-23 HIGH 7.8 CVE-2019-11696 Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can… Firefox 67.0+ Fix from $1,9502019-07-23 HIGH 7.5 CVE-2019-11694 A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to … Firefox 60.7.0 / 67.0+ Fix from $1,9502019-07-23 MEDIUM 6.5 CVE-2019-11697 If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt d… Firefox 67.0+ Fix from $1,6002019-07-23 MEDIUM 6.5 CVE-2019-11699 A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result i… Firefox 67.0+ Fix from $1,6002019-07-23 MEDIUM 6.5 CVE-2019-11700 A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompt… Firefox 67.0+ Fix from $1,6002019-07-23 MEDIUM 6.5 CVE-2019-11702 A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Ex… Firefox 67.0.2+ Fix from $1,6002019-07-23 MEDIUM 6.1 CVE-2019-11701 The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legac… Firefox 67.0+ Fix from $1,6002019-07-23 MEDIUM 5.3 CVE-2019-11698 If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the … Firefox 60.7.0 / 67.0+ Fix from $1,6002019-07-23 CRITICAL 9.8 CVE-2019-11691 A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it h… Firefox 60.7 / 67.0+ Fix from $2,3002019-07-23 CRITICAL 9.8 CVE-2019-11692 A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially ex… Firefox 60.7.0 / 67.0+ Fix from $2,3002019-07-23 MEDIUM 5.9 CVE-2018-12404EPSS 44% A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Ada… Network Security Services 3.41+ Fix from $1,6002019-05-02 HIGH 8.8 CVE-2018-5123 A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.cgi in al… Bugzilla 4.4+ Fix from $1,9502019-04-29