CVEs (1,729)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mozilla3Debian Linux FirefoxThunderbirdNov 25, 2025 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdNov 25, 2025 Jun 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50. |
2Debian Mozilla3Debian Linux FirefoxThunderbirdNov 25, 2025 Jun 11, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox <...Show more |
The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows o...Show more |
2Debian Mozilla3Debian Linux FirefoxThunderbirdNov 25, 2025 Jun 11, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50. |
2Debian Mozilla3Debian Linux FirefoxThunderbirdNov 25, 2025 Jun 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary c...Show more |
169folders AppleBloop+13 more17Airmail EmclientEvolution+14 moreNov 21, 2024 May 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. |
11Apple BloopEmclient+8 more11Airmail EmclientHorde Imp+8 moreNov 21, 2024 May 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications th...Show more |
3Debian Libevent ProjectMozilla4Debian Linux FirefoxLibevent+1 moreMay 13, 2026 Mar 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in b...Show more |
4Mozilla OpensuseOracle+1 more6Firefox LeapLinux+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or ca...Show more |
3Mozilla OpensuseOracle4Firefox LinuxOpensuse+1 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of servi...Show more |
4Mozilla OpensuseOracle+1 more6Firefox LeapLinux+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory co...Show more |
4Mozilla OpensuseOracle+1 more6Firefox LeapLinux+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by lev...Show more |
4Mozilla OpensuseOracle+1 more6Firefox LeapLinux+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service...Show more |
4Mozilla NovellOpensuse+1 more6Firefox LeapLinux+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation...Show more |
4Mozilla NovellOpensuse+1 more6Firefox LeapLinux+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) vi...Show more |
3Mozilla NovellOpensuse5Firefox LeapOpensuse+2 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...Show more |
4Mozilla NovellOpensuse+1 more6Firefox LeapLinux+3 moreMay 6, 2026 Mar 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attack...Show more |
4Debian FedoraprojectMozilla+1 more5Debian Linux FedoraFirefox+2 moreMay 6, 2026 Feb 13, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to...Show more |