VYPR

Vendor CVEs

Mozilla Corporation

All CVEs

3,627 total · sorted by risk
  • CVE-2013-1689MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

  • CVE-2019-9352MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libstagefright, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9349MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-9316MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In libstagefright, there is a missing variable initialization. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112052432

  • CVE-2019-11750MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

  • CVE-2019-11748MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This…

  • CVE-2019-11747MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the…

  • CVE-2019-11742MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.02

    A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow…

  • CVE-2019-11739MedSep 27, 2019
    risk 0.42cvss 6.5epss 0.01

    Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 68.1 and Thunderbird < 60.9.

  • CVE-2019-9816MedJul 23, 2019
    risk 0.42cvss 5.9epss 0.06

    A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled…

  • CVE-2019-11725MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing…

  • CVE-2019-11721MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

  • CVE-2019-11702MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are…

  • CVE-2019-11700MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.

  • CVE-2019-11699MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This could result in user confusion of which site is currently loaded for spoofing attacks. This vulnerability affects Firefox < 67.

  • CVE-2019-11697MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.01

    If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this…

  • CVE-2018-12404MedMay 2, 2019
    risk 0.42cvss 5.9epss 0.44

    A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) and affects all NSS versions prior to NSS 3.41.

  • CVE-2018-18510MedApr 26, 2019
    risk 0.42cvss 6.5epss 0.01

    The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these…

  • CVE-2018-18499MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.01

    A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This…

  • CVE-2018-18497MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.01

    Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file:…

  • CVE-2018-18495MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.02

    WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be…

  • CVE-2018-18494MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.02

    A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This…

  • CVE-2018-12402MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.01

    The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by…

  • CVE-2018-12398MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.02

    By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.

  • CVE-2018-12396MedFeb 28, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR <…

  • CVE-2018-12373MedOct 18, 2018
    risk 0.42cvss 6.5epss 0.02

    dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

  • CVE-2018-12372MedOct 18, 2018
    risk 0.42cvss 6.5epss 0.02

    Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

  • CVE-2018-5185MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

  • CVE-2018-5169MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.

  • CVE-2018-5152MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password…

  • CVE-2018-5133MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes…

  • CVE-2018-5132MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.

  • CVE-2018-5111MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This…

  • CVE-2017-7844MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website to query user history. Note: This issue only affects Firefox…

  • CVE-2017-7830MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.

  • CVE-2017-5420MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

  • CVE-2017-5407MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.03

    Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and…

  • CVE-2016-9067MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

  • CVE-2016-5298MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.01

    A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when the new page is loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox…

  • CVE-2016-5292MedJun 11, 2018
    risk 0.42cvss 6.5epss 0.02

    During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.

  • CVE-2016-10196HigMar 15, 2017
    risk 0.42cvss 7.5epss 0.05

    Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.

  • CVE-2016-5282MedSep 22, 2016
    risk 0.42cvss 6.5epss 0.02

    Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

  • CVE-2016-5271MedSep 22, 2016
    risk 0.42cvss 6.5epss 0.01

    The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.

  • CVE-2016-2827MedSep 22, 2016
    risk 0.42cvss 6.5epss 0.02

    The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.

  • CVE-2016-5260MedAug 5, 2016
    risk 0.42cvss 6.5epss 0.01

    Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.

  • CVE-2016-2839MedAug 5, 2016
    risk 0.42cvss 6.5epss 0.02

    Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allows remote attackers to cause a denial of service (application crash) via a…

  • CVE-2016-2829MedJun 13, 2016
    risk 0.42cvss 6.5epss 0.01

    Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.

  • CVE-2016-2825MedJun 13, 2016
    risk 0.42cvss 6.5epss 0.02

    Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.

  • CVE-2016-2822MedJun 13, 2016
    risk 0.42cvss 6.5epss 0.02

    Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.

  • CVE-2016-2816MedApr 30, 2016
    risk 0.42cvss 6.5epss 0.02

    Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.

Page 29 of 73