VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,370)

  • CVE-2018-12389HigFeb 28, 2019
    risk 0.57cvss 8.8epss 0.02

    Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability…

  • CVE-2018-12388HigFeb 28, 2019
    risk 0.57cvss 8.8epss 0.01

    Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects…

  • CVE-2018-18503HigFeb 5, 2019
    risk 0.57cvss 8.8epss 0.01

    When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65.

  • CVE-2018-12375HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.02

    Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62.

  • CVE-2018-12370HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.01

    In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited if loaded by a malicious site while Reader mode is active, bypassing CSRF protections. This vulnerability affects Firefox < 61.

  • CVE-2018-12364HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.02

    NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability…

  • CVE-2018-12363HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.03

    A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This…

  • CVE-2018-12361HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.03

    An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird <…

  • CVE-2018-12360HigOct 18, 2018
    risk 0.57cvss 8.8epss 0.03

    A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1,…

  • CVE-2018-5130HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

  • CVE-2018-5125HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox…

  • CVE-2017-7845HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.03

    A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This…

  • CVE-2017-7798HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects…

  • CVE-2017-7752HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects…

  • CVE-2017-5436HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1,…

  • CVE-2017-5394HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.01

    A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected.…

  • CVE-2016-9905HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.

  • CVE-2016-9078HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been…

  • CVE-2016-9063CriJun 11, 2018
    risk 0.57cvss 9.8epss 0.05

    An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

  • CVE-2017-5031HigApr 24, 2017
    risk 0.57cvss 8.8epss 0.01

    A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

Page 42 of 169