Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2016-9078 Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in… Firefox Patch available Fix from $1,9502018-06-11 HIGH 8.0 CVE-2016-9070 A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operati… Firefox 50+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9065 The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location … Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9066EPSS 12% A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vul… Firefox 45.5.0 / 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9068 A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox <… Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9072 When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This iss… Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9073 WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox … Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9894EPSS 5% A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buffer, resulting in a potential… Firefox 50.1+ Fix from $1,9502018-06-11 HIGH 7.0 CVE-2016-9077 Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input… Firefox 50.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2016-9067 Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50. Firefox 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.9 CVE-2016-9064 Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perfor… Firefox 45.5.0 / 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.9 CVE-2016-9074 An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NS… Firefox 45.5.0 / 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.9 CVE-2016-9076 An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e1… Firefox 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.3 CVE-2016-9071 Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's bro… Firefox 50.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2016-5287 A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefo… Firefox 49.0.2+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5289 Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that s… Firefox 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5290 Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with… Firefox 45.5.0 / 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-5297 An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affect… Firefox 45.5.0 / 50.0+ Fix from $2,3002018-06-11 CRITICAL 9.8 CVE-2016-9063EPSS 5% An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50. Firefox 2.7.15 / 3.3.7+ Fix from $2,3002018-06-11 HIGH 7.8 CVE-2016-5295 This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozil… Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-5296 A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulne… Firefox 45.5.0 / 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-5299 A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only… Firefox 50.0+ Fix from $1,9502018-06-11 HIGH 7.5 CVE-2016-9061 A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant f… Firefox 50.0+ Fix from $1,9502018-06-11 MEDIUM 6.5 CVE-2016-5292 During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50. Firefox 50.0+ Fix from $1,6002018-06-11 MEDIUM 6.5 CVE-2016-5298 A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when the new pa… Firefox 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.9 CVE-2016-5288 Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This i… Firefox 49.0.2+ Fix from $1,6002018-06-11 MEDIUM 5.5 CVE-2016-5291 A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firef… Firefox 45.5.0 / 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.5 CVE-2016-5293 When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local … Firefox 45.5.0 / 50.0+ Fix from $1,6002018-06-11 MEDIUM 5.5 CVE-2016-5294 The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerabilit… Firefox 45.5.0 / 50.0+ Fix from $1,6002018-06-11 MEDIUM 6.1 CVE-2016-10547 Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape … Nunjucks after 2.4.2 Fix from $1,6002018-05-31