Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2018-18505 An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and… Firefox 60.5.0 / 65.0+ Fix from $2,3002019-02-05 CRITICAL 9.8 CVE-2018-18500EPSS 13% A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object… Firefox 60.5 / 65.0+ Fix from $2,3002019-02-05 CRITICAL 9.8 CVE-2018-18501 Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence o… Firefox 60.5 / 65.0+ Fix from $2,3002019-02-05 CRITICAL 9.8 CVE-2018-18502 Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption a… Firefox 65.0+ Fix from $2,3002019-02-05 CRITICAL 9.8 CVE-2018-18504 A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This result… Firefox 65.0+ Fix from $2,3002019-02-05 HIGH 8.8 CVE-2018-18503 When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some… Firefox 65.0+ Fix from $1,9502019-02-05 MEDIUM 5.9 CVE-2018-18506 When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file … Firefox 65.0+ Fix from $1,6002019-02-05 CRITICAL 9.8 CVE-2018-5186 Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… Firefox 61.0+ Fix from $2,3002018-10-18 MEDIUM 5.3 CVE-2018-12381 Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrect… Firefox 60.2.0 / 62.0+ Fix from $1,6002018-10-18 MEDIUM 5.3 CVE-2018-12382 The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loade… Firefox No fix yet Fix from $1,6002018-10-18 HIGH 8.8 CVE-2018-12375 Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of… Firefox 62.0+ Fix from $1,9502018-10-18 CRITICAL 9.8 CVE-2018-12369 WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain fu… Firefox 60.1.0 / 61.0+ Fix from $2,3002018-10-18 HIGH 8.1 CVE-2018-12368 Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the inte… Firefox 52.9 / 60.1.0+ Fix from $1,9502018-10-18 HIGH 8.8 CVE-2018-12361 An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computatio… Firefox 60.0 / 60.1+ Fix from $1,9502018-10-18 HIGH 7.8 CVE-2016-9069 A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Fir… Firefox 50.0+ Fix from $1,9502018-10-18 MEDIUM 5.9 CVE-2016-9574 nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA. Network Security Services 3.30+ Fix from $1,6002018-07-19 HIGH 7.5 CVE-2018-5180 A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited… Firefox 60.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5153 If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read … Firefox 60.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5174 In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not… Firefox 52.8.0 / 60.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2018-5152 WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic… Firefox 60.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2018-5164 Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This co… Firefox 60.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2018-5165 In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe F… Firefox 60.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2018-5151 Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 60.0+ Fix from $2,3002018-06-11 HIGH 8.2 CVE-2018-5141 A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction.… Firefox 59.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5134 WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that … Firefox 59.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5135 WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this sh… Firefox 59.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2018-5137 A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a… Firefox 59.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2018-5132 The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a mali… Firefox 59.0+ Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2018-5133 If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It… Firefox 59.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2018-5143 URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a… Firefox 59.0+ Fix from $1,6002018-06-11