Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-7753 An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character en… Bleach Patch available Fix from $2,3002018-03-07 HIGH 7.8 CVE-2017-11695 Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attac… Network Security Services No fix yet Fix from $1,9502017-12-27 HIGH 7.8 CVE-2017-11696 Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent atta… Network Security Services No fix yet Fix from $1,9502017-12-27 HIGH 7.8 CVE-2017-11697 The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (fl… Network Security Services No fix yet Fix from $1,9502017-12-27 HIGH 7.8 CVE-2017-11698 Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent att… Network Security Services No fix yet Fix from $1,9502017-12-27 CRITICAL 9.8 CVE-2007-5341 Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8. Firefox after 2.0.0.7 Fix from $2,3002017-08-18 HIGH 7.5 CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re… Network Security Services Patch available Fix from $1,9502017-05-30 CRITICAL 9.8 CVE-2017-5461 Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows rem… Network Security Services 3.21.4 / 3.28.4+ Fix from $2,3002017-05-11 MEDIUM 6.1 CVE-2016-2803 Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers… Bugzilla No fix yet Fix from $1,6002017-04-12 HIGH 8.8 CVE-2016-5283 Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFR… Firefox after 48.0.2 Fix from $1,9502016-09-22 HIGH 7.4 CVE-2016-5284 Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinnin… Firefox after 48.0.2 Fix from $1,9502016-09-22 MEDIUM 6.5 CVE-2016-5282 Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive informa… Firefox after 48.0.2 Fix from $1,6002016-09-22 CRITICAL 9.8 CVE-2016-5281EPSS 5% Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows re… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5280EPSS 5% Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 4… Firefox after 48.0.2 Fix from $2,3002016-09-22 HIGH 8.8 CVE-2016-5278 Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird … Firefox after 48.0.2 Fix from $1,9502016-09-22 CRITICAL 9.8 CVE-2016-5277 Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5276 Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x b… Firefox after 48.0.2 Fix from $2,3002016-09-22 HIGH 8.8 CVE-2016-5275 Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to exe… Firefox after 48.0.2 Fix from $1,9502016-09-22 CRITICAL 9.8 CVE-2016-5274 Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thun… Firefox after 48.0.2 Fix from $2,3002016-09-22 HIGH 8.8 CVE-2016-5273 The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote atta… Firefox after 48.0.2 Fix from $1,9502016-09-22 HIGH 8.8 CVE-2016-5272 The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast … Firefox after 48.0.2 Fix from $1,9502016-09-22 MEDIUM 6.5 CVE-2016-5271 The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds … Firefox after 48.0.2 Fix from $1,6002016-09-22 CRITICAL 9.8 CVE-2016-5270 Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.… Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5257 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow … Firefox after 48.0.2 Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-5256 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory… Firefox after 48.0.2 Fix from $2,3002016-09-22 MEDIUM 6.5 CVE-2016-2827 The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds r… Firefox after 48.0.2 Fix from $1,6002016-09-22 HIGH 8.6 CVE-2016-1951 Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service … Netscape Portable Runtime after 4.11 Fix from $1,9502016-08-07 MEDIUM 5.3 CVE-2016-5267 Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-l… Firefox after 47.0.1 Fix from $1,6002016-08-05 HIGH 8.1 CVE-2016-5266 Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote att… Firefox after 47.0.1 Fix from $1,9502016-08-05 HIGH 8.8 CVE-2016-5264 Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 4… Firefox after 47.0.1 Fix from $1,9502016-08-05