Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2017-5426 On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be ap… Firefox 52.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-5403 When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after… Firefox 52.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5413 A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52. Firefox 52.0+ Fix from $2,3002018-06-11 HIGH 7.5 CVE-2017-5406 A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. … Firefox 52.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5411 A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be free… Firefox 52.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5412 A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird … Firefox 52.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5416 In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vuln… Firefox 52.0+ Fix from $1,9502018-06-11 MEDIUM 5.5 CVE-2017-5409 The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parame… Firefox 45.8.0 / 52.0+ Fix from $1,6002018-06-11 MEDIUM 5.5 CVE-2017-5414 The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to inform… Firefox 52.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2017-5415EPSS 13% An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and furth… Firefox 52.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-5391 Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found… Firefox 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5392 Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruptio… Firefox 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5397 The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for t… Firefox 51.0.3+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5399 Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 52.0+ Fix from $2,3002018-06-11 HIGH 8.8 CVE-2017-5394 A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript even… Firefox 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5381 The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allow… Firefox 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5382 Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal inform… Firefox 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5385 Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to po… Firefox 51.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5388 A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of tim… Firefox 51.0+ Fix from $1,9502018-06-11 MEDIUM 6.1 CVE-2017-5389 WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests… Firefox 51.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2017-5393 The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow mal… Firefox 51.0+ Fix from $1,6002018-06-11 MEDIUM 5.9 CVE-2017-5384 Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information tha… Firefox 51.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-5373 Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that wi… Firefox 45.7.0 / 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5374 Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that… Firefox 51.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2017-5377 A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This … Firefox 51.0+ Fix from $2,3002018-06-11 HIGH 8.1 CVE-2016-9896 Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Fi… Firefox 50.1.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2017-5379 Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51. Firefox 51.0+ Fix from $1,9502018-06-11 MEDIUM 6.1 CVE-2016-9903 Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to b… Firefox 50.1+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2016-9075 An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This… Firefox 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-9080 Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort th… Firefox 50.1+ Fix from $2,3002018-06-11