Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Desktop CRITICAL 9.1
CVE-2017-7758

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vu…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7762

When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used for spoofing…

Fix: 54.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2017-5467

A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability a…

Fix: 52.1 / 52.1.0+
Fix from $1,950 2018-06-11
Enterprise Linux MEDIUM 6.1
CVE-2017-5466

If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the rel…

Fix: 52.1.0 / 53.0+
Fix from $1,600 2018-06-11
Enterprise Linux CRITICAL 9.8
CVE-2017-5456

A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for…

Fix: 52.1.0 / 53.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5459

A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, F…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux HIGH 7.5
CVE-2017-5449

A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerabilit…

Fix: 52.1.0 / 53.0+
Fix from $1,950 2018-06-11
Enterprise Linux HIGH 7.5
CVE-2017-5454

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file …

Fix: 52.1.0 / 53.0+
Fix from $1,950 2018-06-11
Enterprise Linux HIGH 7.5
CVE-2017-5455

The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vuln…

Fix: 52.1.0 / 53.0+
Fix from $1,950 2018-06-11
Enterprise Linux CRITICAL 9.8
CVE-2017-5428

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental exten…

Fix: 52.0.1+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5429

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory co…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5430

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we pr…

Fix: 52.1.0 / 53.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5434

A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Th…

Fix: 45.9.0 / 52.1.0+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5400

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Enterprise Linux Aus CRITICAL 9.8
CVE-2016-9901

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sa…

Fix: 45.6.0 / 50.1+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-5375EPSS 34%

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thu…

Fix: 45.7.0 / 51.0.1+
Fix from $2,300 2018-06-11
Enterprise Linux Desktop HIGH 8.8
CVE-2016-9905

A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and …

Fix: 45.6.0+
Fix from $1,950 2018-06-11
Enterprise Linux Server HIGH 7.5
CVE-2016-9897

Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES.…

Fix: 45.6 / 45.6.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2016-9902

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allow…

Fix: 45.6.0 / 50.1+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2016-9904

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This …

Fix: 45.6.0 / 51.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-12020EPSS 9%

mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof …

Patch available
Fix from $1,950 2018-06-08
Satellite HIGH 7.5
CVE-2016-1000338

In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to…

Fix: 1.56+
Fix from $1,950 2018-06-01
Cloudforms MEDIUM 6.1
CVE-2018-11627

Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

Fix: 2.0.2+
Fix from $1,600 2018-05-31
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8656

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…

Mitigation only
Fix from $1,950 2018-05-22
Mrg Realtime MEDIUM 5.5
CVE-2018-3639EPSS 61%

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory write…

Patch available
Fix from $1,600 2018-05-22
Undertow MEDIUM 6.1
CVE-2018-1067

In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to t…

Fix: 1.4.25 / 2.0.5+
Fix from $1,600 2018-05-21
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-4944EPSS 9%

Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary …

Fix: after 29.0.0.140
Fix from $2,300 2018-05-19
Virtualization Host CRITICAL 9.8
CVE-2018-11236EPSS 7%

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functi…

Fix: after 2.27
Fix from $2,300 2018-05-18
Virtualization Host HIGH 7.8
CVE-2018-11237

An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the targ…

Fix: after 2.27
Fix from $1,950 2018-05-18
Tectonic HIGH 7.5
CVE-2018-5256

CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ w…

Fix: 1.7.9-tectonic.4 / 1.8.4-tectonic.3+
Fix from $1,950 2018-05-18