Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox CRITICAL 9.8
CVE-2024-9680 KEVEPSS 23%

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of t…

Fix: 115.16.0 / 115.16.1+
Fix from $2,300 2024-10-09
Firefox HIGH 8.8
CVE-2023-5217 KEVEPSS 49%

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially ex…

Fix: 1.13.1 / 115.3.1+
Fix from $1,950 2023-09-28
Firefox CRITICAL 9.6
CVE-2022-26486 KEV

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in th…

Fix: 91.6.1 / 91.6.2+
Fix from $2,300 2022-12-22
Firefox HIGH 8.8
CVE-2022-26485 KEVEPSS 14%

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing thi…

Fix: 91.6.1 / 91.6.2+
Fix from $1,950 2022-12-22
Firefox HIGH 8.1
CVE-2020-6819 KEV

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in th…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Firefox HIGH 8.1
CVE-2020-6820 KEVEPSS 6%

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild a…

Fix: 68.6.1 / 68.7.0+
Fix from $1,950 2020-04-24
Firefox HIGH 8.8
CVE-2019-17026 KEVEPSS 47%

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in …

Fix: 68.4.1 / 72.0.1+
Fix from $1,950 2020-03-02
Firefox CRITICAL 10.0
CVE-2019-11708 KEVEPSS 56%

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent …

Fix: 60.7.2 / 67.0.4+
Fix from $2,300 2019-07-23
Firefox HIGH 8.8
CVE-2019-11707 KEVEPSS 38%

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We…

Fix: 60.7.1 / 60.7.2+
Fix from $1,950 2019-07-23
Firefox HIGH 8.8
CVE-2015-4495 KEVEPSS 69%

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same…

Fix: 2.2 / 38.1.1+
Fix from $1,950 2015-08-08
Firefox HIGH 8.8
CVE-2013-1690 KEVEPSS 69%

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle…

Fix: 17.0.7 / 22.0+
Fix from $1,950 2013-06-26
Firefox MEDIUM 6.5
CVE-2013-1675 KEVEPSS 7%

Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initia…

Fix: 17.0.6 / 21.0+
Fix from $1,600 2013-05-16
Firefox CRITICAL 9.8
CVE-2010-3765 KEVEPSS 83%

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.1…

Mitigation only
Fix from $2,300 2010-10-28