Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2017-7844 A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which … Firefox 57.0.1+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-7834 A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policy includi… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-7839 Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScr… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-7840 JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting ex… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7831 A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy o… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7832 The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7833 Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character with some fon… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7837 SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57. Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7838 Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode disp… Firefox after 56.0.2 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7842 If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One o… Firefox after 56.0.2 Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-7811 Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 56.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-7821 A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific… Firefox after 55.0.3 Fix from $2,3002018-06-11 HIGH 8.2 CVE-2017-7813 Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually resu… Firefox after 55.0.3 Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7805 During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some case… Firefox Mitigation only Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7806 A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially ex… Firefox 55.0+ Fix from $1,9502018-06-11 MEDIUM 5.3 CVE-2017-7808 A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the o… Firefox 55.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7812 If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to … Firefox after 55.0.3 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7815 On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as th… Firefox after 55.0.3 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7816 WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow this behavi… Firefox after 55.0.3 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7817 A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. Th… Firefox after 55.0.3 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7820 The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content c… Firefox after 55.0.3 Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7822 The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NIST Special Publication 800-38… Firefox after 55.0.3 Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-7788 When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content S… Firefox 55.0+ Fix from $2,3002018-06-11 HIGH 7.8 CVE-2017-7794 On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only … Firefox 55.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7783EPSS 14% If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal p… Firefox 55.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7790 On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, stack memory data can be copie… Firefox 55.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7797 Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header nam… Firefox 55.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-7804 The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write a… Firefox 52.3.0 / 55.0+ Fix from $1,9502018-06-11 MEDIUM 6.1 CVE-2017-7799 JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is n… Firefox 55.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-7789 If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Sec… Firefox 55.0+ Fix from $1,6002018-06-11