Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2017-7773 Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. Firefox 1.3.10 / 54.0+ Fix from $1,9502019-04-15 HIGH 8.8 CVE-2017-7777 Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. Firefox 1.3.10 / 54.0+ Fix from $1,9502019-04-15 HIGH 8.1 CVE-2017-7771 Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. Firefox 1.3.10 / 54.0+ Fix from $1,9502019-04-15 HIGH 8.1 CVE-2017-7776 Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. Firefox 1.3.10 / 54.0+ Fix from $1,9502019-04-15 HIGH 8.8 CVE-2017-7772 Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. Firefox 1.3.10 / 54.0+ Fix from $1,9502019-04-12 CRITICAL 9.8 CVE-2018-12405 Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence o… Firefox 60.4.0 / 64.0+ Fix from $2,3002019-02-28 CRITICAL 9.8 CVE-2018-12407 A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBu… Firefox 64.0+ Fix from $2,3002019-02-28 CRITICAL 9.8 CVE-2018-18492EPSS 10% A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. … Firefox 60.4.0 / 64.0+ Fix from $2,3002019-02-28 CRITICAL 9.8 CVE-2018-18493 A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bi… Firefox 60.4.0 / 64.0+ Fix from $2,3002019-02-28 CRITICAL 9.8 CVE-2018-18498 A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the… Firefox 60.4 / 64.0+ Fix from $2,3002019-02-28 HIGH 8.8 CVE-2018-12406 Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption a… Firefox 64.0+ Fix from $1,9502019-02-28 HIGH 8.8 CVE-2018-18496 When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack t… Firefox 64.0+ Fix from $1,9502019-02-28 HIGH 7.5 CVE-2018-12401 Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lea… Firefox 63.0+ Fix from $1,9502019-02-28 MEDIUM 6.5 CVE-2018-12402 The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as p… Firefox 63.0+ Fix from $1,6002019-02-28 MEDIUM 6.5 CVE-2018-18494 A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to a… Firefox 60.4.0 / 64.0+ Fix from $1,6002019-02-28 MEDIUM 6.5 CVE-2018-18495 WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could… Firefox 64.0+ Fix from $1,6002019-02-28 MEDIUM 6.5 CVE-2018-18497 Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the ex… Firefox 64.0+ Fix from $1,6002019-02-28 MEDIUM 6.5 CVE-2018-18499 A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection… Firefox 60.2 / 60.2.1+ Fix from $1,6002019-02-28 MEDIUM 5.3 CVE-2018-12400 In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows informati… Firefox 63.0+ Fix from $1,6002019-02-28 MEDIUM 5.3 CVE-2018-12403 If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnera… Firefox 63.0+ Fix from $1,6002019-02-28 CRITICAL 9.8 CVE-2018-12390 Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence o… Firefox 60.3.0 / 63.0+ Fix from $2,3002019-02-28 CRITICAL 9.8 CVE-2018-12392 When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due … Firefox 60.3.0 / 63.0+ Fix from $2,3002019-02-28 HIGH 8.8 CVE-2018-12388 Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption a… Firefox 63.0+ Fix from $1,9502019-02-28 HIGH 8.8 CVE-2018-12389 Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corrup… Firefox 60.3.0+ Fix from $1,9502019-02-28 HIGH 8.8 CVE-2018-12391 During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the pro… Firefox 60.3 / 63.0+ Fix from $1,9502019-02-28 HIGH 7.5 CVE-2018-12393 A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation … Firefox 60.3 / 63.0+ Fix from $1,9502019-02-28 HIGH 7.5 CVE-2018-12395 By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would al… Firefox 60.3 / 63.0+ Fix from $1,9502019-02-28 HIGH 7.1 CVE-2018-12397 A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being… Firefox 60.3.0 / 63.0+ Fix from $1,9502019-02-28 MEDIUM 6.5 CVE-2018-12396 A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential p… Firefox 60.3 / 63.0+ Fix from $1,6002019-02-28 MEDIUM 6.5 CVE-2018-12398 By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (C… Firefox 63.0+ Fix from $1,6002019-02-28