Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2026-14241

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…

Mitigation only
Fix from $2,300 2026-06-30
Thin Vec MEDIUM 5.1
CVE-2026-6654

Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skip…

No fix yet
Fix from $1,600 2026-04-20
Firefox CRITICAL 9.8
CVE-2026-5731

Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of th…

Mitigation only
Fix from $2,300 2026-04-07
Firefox CRITICAL 9.8
CVE-2024-8389

Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Mitigation only
Fix from $2,300 2024-09-03
Firefox CRITICAL 9.8
CVE-2024-8387

Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we p…

Mitigation only
Fix from $2,300 2024-09-03
Firefox MEDIUM 6.1
CVE-2024-0953

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. Thi…

No fix yet
Fix from $1,600 2024-02-05
Common Voice MEDIUM 6.1
CVE-2023-42808

Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for traini…

No fix yet
Fix from $1,600 2023-10-04
Firefox Focus HIGH 7.5
CVE-2023-25743

A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects …

Mitigation only
Fix from $1,950 2023-06-02
Firefox CRITICAL 9.8
CVE-2022-34485

Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs sh…

Mitigation only
Fix from $2,300 2022-12-22
Hubs Cloud MEDIUM 6.1
CVE-2021-29979

Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s prim…

Mitigation only
Fix from $1,600 2021-08-02
Firefox MEDIUM 6.5
CVE-2007-5967

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

Mitigation only
Fix from $1,600 2021-05-17
Firefox MEDIUM 6.1
CVE-2019-17001

A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-si…

Mitigation only
Fix from $1,600 2020-01-08
Firefox MEDIUM 5.3
CVE-2018-12382

The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loade…

No fix yet
Fix from $1,600 2018-10-18
Firefox HIGH 7.5
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some case…

Mitigation only
Fix from $1,950 2018-06-11
Network Security Services HIGH 7.8
CVE-2017-11695

Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attac…

No fix yet
Fix from $1,950 2017-12-27
Network Security Services HIGH 7.8
CVE-2017-11696

Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent atta…

No fix yet
Fix from $1,950 2017-12-27
Network Security Services HIGH 7.8
CVE-2017-11697

The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (fl…

No fix yet
Fix from $1,950 2017-12-27
Network Security Services HIGH 7.8
CVE-2017-11698

Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent att…

No fix yet
Fix from $1,950 2017-12-27
Bugzilla MEDIUM 6.1
CVE-2016-2803

Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers…

No fix yet
Fix from $1,600 2017-04-12
Firefox HIGH 8.8
CVE-2016-2805

Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory …

Mitigation only
Fix from $1,950 2016-04-30
Firefox MEDIUM 5.3
CVE-2016-1948

Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attack…

Mitigation only
Fix from $1,600 2016-01-31
Firefox HIGH 8.8
CVE-2016-1945

The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other…

Mitigation only
Fix from $1,950 2016-01-31
Firefox CRITICAL 9.8
CVE-2016-1944

The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of servic…

No fix yet
Fix from $2,300 2016-01-31
Firefox HIGH 10.0
CVE-2015-4497EPSS 8%

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allow…

Mitigation only
Fix from $1,950 2015-08-29
Firefox MEDIUM 6.8
CVE-2015-2727

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chro…

Mitigation only
Fix from $1,600 2015-07-06
Firefox HIGH 7.5
CVE-2015-0814

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory…

Mitigation only
Fix from $1,950 2015-04-01
Network Security Services HIGH 7.5
CVE-2013-1741

Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have …

Mitigation only
Fix from $1,950 2013-11-18
Network Security Services MEDIUM 5.8
CVE-2013-5606

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return va…

Mitigation only
Fix from $1,600 2013-11-18
Bugzilla MEDIUM 5.0
CVE-2012-5884

The User.get method in Bugzilla/WebService/User.pm in Bugzilla 4.3.2 allows remote attackers to obtain sensitive information about the saved searches…

Mitigation only
Fix from $1,600 2012-11-16
Zamboni HIGH 7.4
CVE-2012-5822

The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,950 2012-11-04